
CVE-2025-69212-for-myself
Proof-of-concept exploit for CVE-2025-69212 that authenticates to a URL with admin credentials and triggers a reverse shell to the specified attacker…

Proof-of-concept exploit for CVE-2025-69212 that authenticates to a URL with admin credentials and triggers a reverse shell to the specified attacker…

JavaScript payloads that weaponize XSS bugs into critical impact, enabling account takeover and admin creation on popular CMS platforms for pentest…

Exploit PoC for CVE-2026-64638 demonstrating WordPress pre-auth XSS to RCE. Captures an admin Application Password, publishes a page, uploads a…

Automated Active Directory privilege escalation tool using DCSync to extract krbtgt hash and forge a golden ticket for enterprise admin access.

Proof-of-concept for a stored Cross-Site Scripting (XSS) vulnerability in Pluck CMS 4.7.18 installation. Injects payload via cont1 and cont2…

TotalCMS is affected by Arbitrary File Upload - XSS vulnerability which allows Cross-Site Scriting (XSS) Stored and also stealing session cookies

Alex Reservations: Smart Restaurant Booking <= 2.2.3 - Authenticated (Admin+) Arbitrary File Upload

Exploit for CVE-2026-38526 targeting Krayin CRM's unrestricted file upload. Uploads PHP webshell for remote command execution via admin credentials.

Exploit for CVE-2026-15013: unauthenticated SAML auth bypass via algorithm confusion. Forges SAML responses to gain admin access and deploy…

Proof-of-concept exploit script for command injection (CVE-2026-27626) in OliveTin's password argument handling, enabling RCE via crafted API…

Multi-vector exploit framework for CVE-2026-60206 targeting Oracle WebLogic Server SAML authentication bypass, with mass scanning, safe detection,…

Exploit for CVE-2023-22515 enabling remote code execution on Confluence servers via custom plugin upload after gaining admin access.

Python exploit for CVE-2023-32315 targeting Openfire servers. Bypasses admin panel authentication via Unicode path traversal to create an…

Exploit script for CVE-2026-41462, a critical unauthenticated stacked SQL injection in ProjeQtor ≤12.4.3. Creates admin accounts via crafted…

Open-Source Remote Administration Tool For Windows C# (RAT)

Unauthenticated remote code execution exploit for the WC Designer Pro WordPress plugin. Automates detection, file upload, and shell access via a…

CVE-2025-26633 (CVSS 7.8) – Zero-day MMC .msc EvilTwin LPE actively exploited by Water Gamayun APT. PoC creates local admin via malicious MSC file on…

Proof-of-concept exploit for CVE-2024-21683, a remote code execution vulnerability in Atlassian Confluence. Executes a JavaScript payload against…