
BlueBunny
BLE-based C2 server for Hak5 Bash Bunny enabling wireless command injection, payload delivery, and remote control over Bluetooth Low Energy.

BLE-based C2 server for Hak5 Bash Bunny enabling wireless command injection, payload delivery, and remote control over Bluetooth Low Energy.

CTT-PAN-OS-Exploit – CVE-2024-3400 (CVSS 10.0) with Convergent Time Theory enhancement. Uses α = 0.0302011 temporal dispersion, 33-layer phase…


CVE-2022-26134 Confluence OGNL Injection POC

PoC exploit for CVE-2020-11800, a command injection in Zabbix Server via malicious agent auto-registration, with Python-based payload delivery and…

Python script for exploiting command injection in Open PLC Webserver v3

Remote OS Command Injection in TastyIgniter v3.0.7 Sendmail Path field

[CVE-2021-22123] Fortinet FortiWeb Authenticated OS Command Injection

CVE-2025-54123 Hoverfly Authenticated Middleware Command Injection RCE

pdf_info <= 0.5.3 OS Command Injection

OpenSTAManager v2.9.8 and earlier versions contain a critical OS Command Injection vulnerability in the P7M (signed XML) file decoding function.

CVE-2025-69212 - OpenSTAManager has an OS Command Injection in P7M File Processing

upsmon: remote OS command injection (RCE) via attacker-controlled ups.alarm in NOTIFYCMD execution

PoC for CVE-2026-46420, command injection in shivammathur/setup-php via repository-controlled PHP version resolution.

OliveTin is a self-hosted web UI for exposing predefined shell commands to end users. This repository contains a proof-of-concept demonstrating two…

Python RCE exploit for Sendmail with ClamAV-Milter <0.91.2 (CVE-2007-4560). Remote root command injection via SMTP RCPT TO headers.

Python PoC for CVE-2025-60787, authenticated OS command injection RCE in motionEye <= 0.43.1b4 via unsanitized image_file_name config

A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter.