
CVE-2026-11112-XXE-via-SVG-Image-Upload
Demonstrates XXE via SVG upload with a vulnerable Flask/lxml parser and an exploit script for arbitrary file read, SSRF, and denial-of-service…

Demonstrates XXE via SVG upload with a vulnerable Flask/lxml parser and an exploit script for arbitrary file read, SSRF, and denial-of-service…

Proof-of-concept exploit for CVE-2021-45026 targeting Rocket Software Zena. Chains stored XSS to remote code execution via REST API task injection on…

PoC exploit for CVE-2019-16759 enabling remote code execution on vBulletin 5.0.0–5.6.2 via malicious POST request due to input validation flaw.

Exploiting CVE-2021-44228 in Unifi Network Application for remote code execution and more.

Proof of Concept of CVE-2022-30190

This Python proof-of-concept targets a vulnerable MCP (Model Context Protocol) service exposed by the target application. The vulnerability allows an…

Requests Baskets (CVE-2023-27163) and Mailtrail v0.53

CVE-2023-26039 - ZoneMinder. Any authenticated user can construct an api command to execute any shell command as the web user.

Python-based exploit for CVE-2021-45428, targeting a specific web application vulnerability for penetration testing and security assessment.

Dockerized lab environment for safely practicing CVE-2021-44228 (Log4Shell) exploitation. Includes attacker LDAP server and vulnerable Java…

Church Rota version 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permission in order to…

Proof-of-concept exploit for CVE-2021-21315, demonstrating remote code execution in a web application framework. Intended for security testing and…

Exploit for CVE-2018-16156 targeting a remote code execution vulnerability in a web application, providing a proof-of-concept payload for security…

Primefaces <= 5.2.21, 5.3.8 or 6.0 - Remote Code Execution Exploit

automate CVE-2015-9235 exploitation

Proof-of-concept exploit for CVE-2018-19246 with Docker-based deployment and Pocsuite integration for automated web application vulnerability testing.

Modified proof-of-concept exploit for CVE-2021-31630 targeting a web application vulnerability with reverse shell payload generation and remote code…

Scanner and proof-of-concept exploit for Log4j RCE (CVE-2021-44228). Creates a vulnerable application and runs the exploit with a netcat listener.