
eLabFTW-1.8.5-EntityController-Arbitrary-File-Upload-RCE
Exploit for eLabFTW 1.8.5 (CVE-2019-12185) enabling arbitrary file upload and remote code execution via EntityController. Generates a PHP shell in…

Exploit for eLabFTW 1.8.5 (CVE-2019-12185) enabling arbitrary file upload and remote code execution via EntityController. Generates a PHP shell in…

Proof-of-concept exploit for CVE-2022-29464 enabling unrestricted file upload and remote code execution on vulnerable WSO2 products, with a custom…

A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass

Automated Reverse Shell Exploit via WebSocket | Havoc-C2-SSRF with RCE

Working proof-of-concept exploit for CVE-2019-0708 (BlueKeep) that spawns a remote shell on vulnerable Windows systems. Run with Python 3.

The Joomla extension Page Builder CK is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to…

Scanner and proof-of-concept exploit for Log4j RCE (CVE-2021-44228). Creates a vulnerable application and runs the exploit with a netcat listener.

CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because the tool listens on 0.0.0.0 by…

Proof-of-concept exploit for CVE-2024-10586 targeting WordPress Debug Tool plugin. Automates arbitrary file upload leading to remote code execution…

Proof-of-concept exploit for CVE-2024-9932, an unauthenticated arbitrary file upload vulnerability in the Wux Blog Editor WordPress plugin, enabling…

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full…

Church Rota version 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permission in order to…

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

SpiderControl SCADA Web Server File Upload Vulnerability

Proof-of-concept for Log4Shell (CVE-2021-44228) demonstrating remote code execution via JNDI injection, including vulnerable server setup, exploit…

CVE-2024-48061 Langflow vulnerable to remote code execution. Poc

Proof-of-concept exploit for authenticated PHP code injection in ISPConfig <= 3.2.11, enabling remote code execution via unsanitized language file…

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…