
exploit-CVE-2017-7494
SambaCry exploit and vulnerable container (CVE-2017-7494)

SambaCry exploit and vulnerable container (CVE-2017-7494)

CVE-2026-31816 - Budibase Authentication Bypass to RCE

The full repo of all the labs available as part of the benchmark

Single-file PoC for Rails CVE-2026-66066: arbitrary file read, secret recovery, threaded scanning, and conditional RCE via signed image variations.

Payload generator and proof-of-concept exploit for CVE-2018-12533 (Richfaces deserialization/EL injection) with Docker-based vulnerable environment…

A curated list of resources (books, tutorials, courses, tools and vulnerable applications) for learning about Exploit Development

🧙♂️ Node.js Command & Control for Script-Jacking Vulnerable Electron Applications

Local privilege escalation exploit for CVE-2023-21768 targeting Windows AFD driver. Elevates arbitrary process to SYSTEM using I/O Ring read/write…

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

CVE-2020-15368, aka "How to exploit a vulnerable driver"

Proof-of-concept exploit for CVE-2020-0796 (SMBGhost) remote overflow vulnerability. Python script to check and trigger the SMBv3 compression bug on…

RCE exploit toolkit for CVE-2025-55182 and CVE-2025-66478 in React Server Components. Includes multiple exploit variants, detection scripts, a…

Pre-auth RCE proof-of-concept for Apache OFBiz CVE-2023-49070, exploiting XML-RPC Java deserialization to achieve remote code execution on vulnerable…

all 4.4 ubuntu aws instances are vulnerable

A purposely vulnerable application in order to demonstrate PHP payload smuggling techniques for PNG files.

Python exploit for Oracle WebLogic CVE-2019-2725, enabling unauthenticated remote code execution via crafted HTTP requests to vulnerable servers.

Intentionally vulnerable Next.js application demonstrating CVE-2025-55182 RCE via unsafe deserialization in React Server Components. Includes exploit…

Exploit for PHP CGI Argument Injection (CVE-2024-4577) enabling remote code execution on vulnerable Windows servers running Apache and PHP-CGI.…