
CVE-2025-10353-POC
Exploit for CVE-2025-10353. Unauthenticated File Upload on Melis Platform Framework that leads to RCE

Exploit for CVE-2025-10353. Unauthenticated File Upload on Melis Platform Framework that leads to RCE

Python proof-of-concept demonstrating an authentication bypass in pac4j JWT by crafting a JWE token with an unsigned inner JWT, allowing privilege…

Invoke-ArgFuscator is an open-source, cross-platform PowerShell module that helps generate obfuscated command-lines for common system-native…

Authenticated RCE exploit for WBCE CMS <= 1.6.3 that creates a malicious module zip with a PHP reverse shell and netcat listener.

Exploit module for FreePBX delivering a reverse shell payload to achieve remote command execution and persistent shell access, designed for…

This module exploits a vulnerability in WinRAR (CVE-2023-38831). When a user opens a crafted RAR file and its embedded document, a script is…

Metasploit module for CVE-2025-24071 - Windows NTLM Hash Leak via .library-ms

Rejetto HTTP File Server (HFS) 2.x - Unauthenticated RCE exploit module (CVE-2024-23692)

Exploits the arbitrary file write bug in proftpd (CVE-2015-3306) attempts code execution

### This module requires Metasploit: https://metasploit.com/download# Current source: https://github.com/rapid7/metasploit-framework##class…

CLI rewrite of the Drupalgeddon2 (CVE-2018-7600) PoC — for authorised testing/education

PoC tools for CVE-2026-58457: Unauthenticated OS Command Injection leading to remote root on Shenzhen Aitemi M300 Wi-Fi Repeater (MT02). Includes…

Python RCE PoC with reverse-shell listener for CVE-2026-42945 (NGINX Rift)

FreePBX Pre-Auth SQLi to RCE (CVE-2025-57819) — All-in-One Exploit

Python-based proof-of-concept and exploit for CVE-2021-46422, with a scanner mode and a command-execution exploit module for authorized security…

This script is used for automating exploit for Oracle Ebussiness (EBS) for CVE 2022-21587 ( Unauthenticated File Upload For Remote Code Execution)

POC for CVE-2025-24054

Metasploit module generating a malicious Word document to exploit CVE-2018-8174, a VBScript memory corruption vulnerability in Microsoft Office…