
CVE-2026-25916-Roundcube-Webmail-DOM-based-XSS-Exploit-via-SVG-href-Attribute
Python exploit for Roundcube Webmail DOM-based XSS (CVE-2026-25916) via SVG href attributes, enabling session hijacking and data exfiltration through…

Python exploit for Roundcube Webmail DOM-based XSS (CVE-2026-25916) via SVG href attributes, enabling session hijacking and data exfiltration through…

An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

Proof-of-concept exploit for CVE-2026-26215, an unauthenticated remote code execution vulnerability in manga-image-translator via unsafe pickle…

A stealthy Python based Windows backdoor that uses Github as a command and control server

Proof-of-concept demonstrating remote code execution via prompt injection in GitHub Copilot Chat, using a crafted Python file to trigger a…

PoC exploit for CVE-2018-11235 allowing RCE on git clone --recurse-submodules

Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload

RCE RESPONSIVE filemanager v.9.14.0

RCE RESPONSIVE filemanager v.9.14.0

CVE-2022-22965\Spring-Core-RCE堪比关于 Apache Log4j2核弹级别漏洞exp的rce一键利用

CVE-2022-29221 Proof of Concept Code - Smarty RCE

Batch script exploit for CVE-2020-27955, achieving remote code execution via Git LFS on Windows. Targets git, GitHub CLI, VS Code, and other Git…

Exploit against Grav CMS (versions below 1.7.45) that allows Remote Code Execution for an authenticated user - CVE-2024-28116

Python exploit for CVE-2023-35885 targeting CloudPanel v2.0.0–v2.3.0. Injects a webshell via a crafted serialized cookie to achieve remote code…


A working (at least for me :] ) exploit for CVE-2025-25257