
CVE-2020-9496
Manual exploit for CVE-2020-9496, an unauthenticated Java deserialization RCE in Apache OFBiz XML-RPC, with step-by-step instructions for payload…

Manual exploit for CVE-2020-9496, an unauthenticated Java deserialization RCE in Apache OFBiz XML-RPC, with step-by-step instructions for payload…

One-Day POC | GeoServer Unauthenticated SQL injection to complete RCE

A Proof-Of-Concept for the CVE-2021-44228 vulnerability.

Node.js reverse shell payload generator for penetration testing. Creates bind and reverse shells in JavaScript.

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address

This is my implementation of JSRat.ps1 in Python so you can now run the attack server from any OS instead of being limited to a Windows OS with…

Exploit PoC for CVE-2025-53770 enabling webshell upload to SharePoint, ValidationKey extraction, signed ViewState generation, and remote code…

BIG-IP F5 Remote Code Execution

Chamilo LMS Unauthenticated Big Upload File that allows remote code execution

Proof-of-concept exploit for CVE-2020-0688 providing remote code execution and reverse bind shell against Microsoft Exchange servers.

Nginx CVE-2019-20372 PoC, Unauthenticated File Upload Exploit

An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution

Repository to exploit CVE-2023-46604 reported for ActiveMQ

POC for CVE-2023-4220 - Chamilo LMS Unauthenticated Big Upload File Remote Code Execution

Java-based proof-of-concept exploit for CVE-2021-44228 (Log4Shell) enabling remote command execution, OS information gathering, and arbitrary…

CVE-2016-5195 dirtycow by timwr automated multi file patch tool

Proof-of-concept exploit for CVE-2023-4220: unauthenticated file upload in Chamilo LMS enabling stored XSS and remote code execution via web shell…

Unauthenticated remote code execution exploit for Wing FTP Server < 7.4.4, enabling command execution and reverse shells via Lua injection in session…