
CVE-2026-0740
Automated mass exploiter for CVE-2026-0740, an unauthenticated arbitrary file upload in Ninja Forms File Uploads plugin, enabling remote code…

Automated mass exploiter for CVE-2026-0740, an unauthenticated arbitrary file upload in Ninja Forms File Uploads plugin, enabling remote code…

Exploit for CVE-2025-10353. Unauthenticated File Upload on Melis Platform Framework that leads to RCE

Microsoft just released emergency patches for CVE-2026-21509, a zero-day in the Office Suite that bypasses OLE/COM mitigations when a user simply…

CVE-2026-32475 The Elementor Pro Forms File Upload field handles validation and file processing in two separate loops with different handling of…

Reproduces fastjson 1.2.83 @JSONType RCE with a vulnerable Spring Boot target and ASM-based payload generator using HTTP or file protocol jar chains.

Generates WebP images that trigger CVE-2023-4863 heap buffer overflow in libwebp, using tunable OFFSET/VALUE constants for exploit testing and…

Proof of Concept (PoC) of CVE-2025-69212 related with P7M File Processing

🐾Dogwalk PoC (using diagcab file to obtain RCE on windows)

A QoL tool to obfuscate shellcode. In the future will be able to chain encoding/encryption/compression methods.

Hide your payload into .jpg file

A payload delivery system which embeds payloads in an executable's icon file!

Demonstrates XXE via SVG upload with a vulnerable Flask/lxml parser and an exploit script for arbitrary file read, SSRF, and denial-of-service…

Found a 0-Day in Ghidra: Shared Project File Became a Code Execution Vector

Generates a PDF with embedded JavaScript to demonstrate CVE-2026-21013, an OpenAction injection leading to script execution in vulnerable PDF readers.

CVE-2026-63223 — CI4RCE: CodeIgniter 4 is_image/mime_in File Upload RCE. Magic bytes bypass (getExtension vs getClientExtension). CVSS 9.8 | CWE-434…

Exploit for Apache Kyuubi path traversal (CVE-2026-52680) achieving unauthenticated arbitrary file write and code execution via profile.d shell…


CVE-2026-63223 PoC — CodeIgniter 4 is_image/mime_in File Upload RCE (CVSS 9.8). Unauthenticated remote code execution via unrestricted file upload…