
CVE-2026-25916-Roundcube-Webmail-DOM-based-XSS-Exploit-via-SVG-href-Attribute
Python exploit for Roundcube Webmail DOM-based XSS (CVE-2026-25916) via SVG href attributes, enabling session hijacking and data exfiltration through…

Python exploit for Roundcube Webmail DOM-based XSS (CVE-2026-25916) via SVG href attributes, enabling session hijacking and data exfiltration through…

Proof-of-concept exploit for CVE-2026-26215, an unauthenticated remote code execution vulnerability in manga-image-translator via unsafe pickle…

Migration, Backup, Staging <= 0.9.123 - Unauthenticated Arbitrary File Upload

CVE-2022-22965\Spring-Core-RCE堪比关于 Apache Log4j2核弹级别漏洞exp的rce一键利用

RCE RESPONSIVE filemanager v.9.14.0

A working (at least for me :] ) exploit for CVE-2025-25257

CVE-2022-29221 Proof of Concept Code - Smarty RCE

Batch script exploit for CVE-2020-27955, achieving remote code execution via Git LFS on Windows. Targets git, GitHub CLI, VS Code, and other Git…


An automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.

Exploit against Grav CMS (versions below 1.7.45) that allows Remote Code Execution for an authenticated user - CVE-2024-28116

Python exploit for CVE-2023-35885 targeting CloudPanel v2.0.0–v2.3.0. Injects a webshell via a crafted serialized cookie to achieve remote code…

Proof-of-concept demonstrating remote code execution via prompt injection in GitHub Copilot Chat, using a crafted Python file to trigger a…

PoC exploit for CVE-2018-11235 allowing RCE on git clone --recurse-submodules

RCE RESPONSIVE filemanager v.9.14.0

A stealthy Python based Windows backdoor that uses Github as a command and control server