
CVE-2026-52806
Gogs RCE via argument injection in git rebase (CWE-88) — Python PoC. CVE-2026-52806

Gogs RCE via argument injection in git rebase (CWE-88) — Python PoC. CVE-2026-52806

Exploit for CVE-2024-32002, a Git RCE vulnerability that uses recursive submodule cloning and symlinks to execute arbitrary commands on Windows and…

this is a metasploit exploit module for CVE-2024-25096 and CVE-2023-3452

Exploit CVE-2025-49844 Redis Lua UAF vulnerability to execute arbitrary shellcode and establish persistent backdoor access on vulnerable Redis…

Proof-of-concept exploit and Docker lab for CVE-2026-35194, an Apache Flink SQL code injection enabling remote code execution on TaskManagers via the…

Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp…

Python proof-of-concept exploit for Apache Struts2 CVE-2018-11776 remote code execution vulnerability, with Docker container for testing against…

Working Python test and PoC for CVE-2018-11776, includes Docker lab

Proof-of-Concept exploit for CVE-2025-9074 - Unauthenticated Docker API exposure allowing arbitrary container creation and host filesystem access.

My take on the needrestart Python CVE-2024-48990

Stealth dropper executing remote binaries without dropping them on disk .(HTTP3 support, ICMP support, invisible tracks, cross-platform,...)

Advisory and proof of concept for CVE-2019-12180, demonstrating arbitrary Groovy code execution in SoapUI and ReadyAPI via malicious project files.

Turns any rooted phone into the legendary USB Rubber Ducky. Android USB HID Keystroke Injector

Data-only local privilege escalation exploit for Linux kernel io_uring CVE-2024-0582, using sprayed file structures and ext4_file_operations hooks to…

MariaDB 13.0.1-rc RCE lab — priv-esc + heap UAF + JOP chain to system() as uid 999(mysql) on stock Docker image. Found with RAPTOR and…

Exploit Development for CVE-2023-6553 on Backup Plugin in Wordpress

Code sample for using exploit CVE-2019-5736 to mine bitcoin with no association to original container or user.

fastjson-1.2.58-rce with h2 database