
CVE-2025-10353-POC
Exploit for CVE-2025-10353. Unauthenticated File Upload on Melis Platform Framework that leads to RCE

Exploit for CVE-2025-10353. Unauthenticated File Upload on Melis Platform Framework that leads to RCE

CVE-2024-4367 is a critical vulnerability (CVSS 9.8) in PDF.js, allowing arbitrary JavaScript code execution due to insufficient type checks on the…

Educational Python target range simulating CVE-2026-22807, an AI supply chain RCE via TOCTOU in model loading. Includes vulnerable library, PoC…

Rust-based exploit generator for CVE-2026-29000, an authentication bypass in pac4j-jwt via alg:none JWT nested in JWE, automating JWKS retrieval and…

POC | GeoServer Unauthenticated SQL injection to complete RCE

Multi-architecture assembler framework that converts assembly source into machine code for Arm, x86, MIPS, PowerPC, RISC-V, and more, with a…

Reproduces fastjson 1.2.83 @JSONType RCE with a vulnerable Spring Boot target and ASM-based payload generator using HTTP or file protocol jar chains.

Self-contained Docker lab that reproduces CVE-2025-24893, an unauthenticated SSTI-to-RCE in XWiki SolrSearch, and compares vulnerable vs patched…

PoC for CVE-2026-9090 — Casdoor SAML signature bypass (CWE-347). Reproduction-only; coordinated via CERT/CC VU#780781.

PoC for CVE-2025-64512: pdfminer.six CMapDB pickle deserialization RCE via crafted PDF

During the exploitation phase of a pen test or ethical hacking engagement, you will ultimately need to try to cause code to run on target system…

A QoL tool to obfuscate shellcode. In the future will be able to chain encoding/encryption/compression methods.

CVE-2026-64638 - Draft or TODO

Wordpress Pre-auth XSS to RCE exploit PoC (xss2shell & CVE-2026-64638)

Proof-of-concept exploit for CVE-2026-70553, enabling unauthenticated RCE in MaxSite CMS via persistent PHP injection into database.php through the…

Invoke-ArgFuscator is an open-source, cross-platform PowerShell module that helps generate obfuscated command-lines for common system-native…

CVE-2026-63223 PoC — CodeIgniter 4 is_image/mime_in File Upload RCE (CVSS 9.8). Unauthenticated remote code execution via unrestricted file upload…

Unfixed Windows PowerShell Filename Code Execution POC