
EXPLOIT-CVE-2025-27515
PoC of CVE-2025-27515

PoC of CVE-2025-27515

CVE-2025-55182 — Unauthenticated RCE in React Server Components (React2Shell). CVSS 10.0 exploit tool for authorized penetration testing.

The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the…

Piotnet Addons for Elementor Pro <= 7.1.70 - Unauthenticated Arbitrary File Upload → RCE

Altay takımı haftalık sunumu için yaptığım cve-2025-22457 zafiyeti demo uygulaması

Exploit tool for CVE-2025-55182 and CVE-2025-66478 in React Server Components and Next.js, featuring RCE gadgets, file read/write, OOB callbacks, and…

Proof-of-concept remote code execution exploit targeting OpenSMTPD versions 6.4.0 to 6.6.1, delivering a reverse shell via crafted SMTP commands.

CVE-2023-27163 Request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}.…

Proof-of-concept exploit for CVE-2019-0752 targeting Internet Explorer 11 on Windows 10 x64. Uses JavaScript DOM manipulation and special address…

Proof-of-concept exploit for CVE-2019-0708 (BlueKeep) targeting Windows RDP, with shellcode for x86 systems. Intended for authorized security testing…

PowerShell exploit for CVE-2021-1675 (PrintNightmare) performing local privilege escalation via Print Spooler, with custom DLL payload injection and…

Proof-of-concept exploit for CVE-2024-10793 targeting WordPress wp-security-audit-log plugin. Demonstrates account takeover, privileged user…

CVE-2019-17564 Apache Dubbo deserialization RCE

AlphaWeb XE, the embedded web server running on AlphaCom XE, has a vulnerability which allows to upload PHP files leading to RCE once the…

Newscrunch <= 1.8.4 - Authenticated (Subscriber+) Arbitrary File Upload


Rust-based DLL hijacking loader for MobaXterm (CVE-2026-6421) with persistence

Penetration testing framework with AI-driven decision engine