
FuguHub-8.4-Authenticated-RCE-CVE-2024-27697
Authenticated remote code execution exploit for FuguHub 8.4, injecting a Lua reverse shell via the customizable About page in the admin panel.

Authenticated remote code execution exploit for FuguHub 8.4, injecting a Lua reverse shell via the customizable About page in the admin panel.

Python exploit for CVE-2026-55579, an unauthenticated RCE in Pheditor via hardcoded default credentials. Executes commands and uploads files through…

JavaScript payloads that weaponize XSS bugs into critical impact, enabling account takeover and admin creation on popular CMS platforms for pentest…

Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin…

Proof-of-concept exploit for CVE-2024-27956, a SQL injection in ValvePress Automatic WordPress plugin. Automates user creation with admin privileges…

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

Proof-of-concept exploit demonstrating XSS-to-RCE chain in pfSense 2.4.4-p2/p3 via phishing, with custom JavaScript and PHP webshell payloads for…

Pre-auth SQL injection to remote code execution exploit for WordPress REST API batch endpoint. Creates admin account and executes system commands via…

Exploit for ActiveMQ deserialization RCE (CVE-2015-5254) using jmet to send crafted serialized payloads via OpenWire port 61616, with command…

Exploit for CVE-2020-23839, a reflected XSS in GetSimple CMS v3.3.16 admin login, chaining to remote code execution via a PHP backdoor WebShell.

Proof-of-concept exploit and technical advisory for an Admin+ arbitrary file upload to remote code execution vulnerability in Everest Toolkit…

PoC exploit for FreePBX 16 chaining CVE-2025-57819 (unauthenticated stacked SQL injection) and CVE-2025-61678 (arbitrary file upload/path traversal)…

Proof-of-concept exploit for WordPress REST API time-based blind SQL injection (CVE-2026-63030, CVE-2026-60137) with full chain escalation to remote…

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

Exploit for authentication bypass in WP Time Capsule plugin (<1.21.16). Steals admin cookie and uploads webshell.

Exploit for Joomla core directory traversal (CVE-2020-24597) enabling remote code execution via admin account, with PoC script for privilege…

PoC exploit for Wolf CMS <= 0.8.3.1: authenticates to Admin, writes an arbitrary PHP file to /public via FileManagerController, and executes commands…

Proof-of-concept exploit for CVE-2026-63030 chaining REST API route confusion, SQL injection, oEmbed cache poisoning, and Customizer privilege…