
Pluck-CMS-Stored-XSS---Installation
pluck CMS 4.7.18 is affected by a Multiple Stored Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a…

pluck CMS 4.7.18 is affected by a Multiple Stored Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a…

Python exploit for Serv-U SSH vulnerability (CVE-2021-35211) with multiple payload modes: stage, exec, and download-execute, enabling shellcode…

A cross-platform C2/teamserver supporting multiple transport protocols, written in Go.

Multiple Cross Site Scripting vulnerability in ConcreteCMS v.9.2.1 allows a local attacker to execute arbitrary code via a crafted script to the…

CVE-2021-46076 - Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in…

MySQL-Fu is a Ruby based MySQL Client Script I wrote. It does most of the stuff a normal MySQL client might do: SQL Shell, Update/Delete/Drop…

CVE-2026-5718: Unauthenticated File Upload To RCE in DnD Upload CF7 Plugin

Automated scanner for CVE-2026-6271, a critical unauthenticated arbitrary file upload leading to RCE in the WordPress Career Section plugin. Supports…

Proof-of-concept exploit for CVE-2022-44830, a CSV injection vulnerability in Sourcecodester Event Registration App v1.0. Demonstrates remote code…


Zimbra CVE-2022-27925 PoC

Exploit for CVE-2009-4623: remote file inclusion in Advanced Comment System 1.0 enabling arbitrary PHP code execution and reverse shell via ACS_path…

Proof-of-concept exploit for CVE-2022-47966, a pre-authentication remote code execution vulnerability in multiple ManageEngine products via SAML…

Proof-of-concept exploit for unauthenticated remote code execution in Tatsu Builder WordPress plugin (CVE-2021-25094). Supports multiple shell…

WordPress File Upload RCE Exploit

Python proof-of-concept for detecting CVE-2023-27372 in SPIP CMS. Scans single or multiple URLs for the vulnerability and outputs results to terminal…

This repository showcases a fully self-developed Proof-of-Concept (PoC) for CVE-2018-7600, widely known as Drupalgeddon 2. This critical…

CVE‑2025‑3515 — Drag and Drop Multiple File Upload for Contact Form 7