
CVE-2022-22965-PoC_Payara
Proof-of-concept exploit for CVE-2022-22965 in Payara/Glassfish, demonstrating arbitrary file download via web root manipulation. Includes Docker…

Proof-of-concept exploit for CVE-2022-22965 in Payara/Glassfish, demonstrating arbitrary file download via web root manipulation. Includes Docker…

CVE-2024-23739

Proof-of-concept exploit for CVE-2024-27956 SQL injection in ValvePress Automatic plugin. Creates admin users in WordPress to achieve remote code…

Missing Authentication for Critical Function (CWE-306)-Exploit

Code sample for using exploit CVE-2019-5736 to mine bitcoin with no association to original container or user.


Go PoC for CVE-2025-32433 — unauthenticated RCE in Erlang/OTP SSH.

The full repo of all the labs available as part of the benchmark


exploit for CVE-2022-42889

CVE-2026-33017 Exploit | by infrar3d

Reproducer for CVE-2026-33454: Apache Camel camel-mail header injection to RCE via camel-exec

Ethical, network-isolated Docker lab reproducing CVE-2026-26030 — Semantic Kernel in-memory vector store filter eval() RCE (patched in 1.39.4)

Full Metasploit exploitation walkthrough against Metasploitable2 — vsftpd backdoor, Samba CVE-2007-2447, UnrealIRCd backdoor, Netcat exfiltration,…

Python exploit for vsftpd 2.3.4 - Backdoor Command Execution

Mass exploit toolkit for CVE-2026-5524, an unauthenticated file upload RCE in Divi Form Builder. Features multi-threaded scanning, WAF bypass…

Metasploit module for CVE-2018-4878