
wp2shell
unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)
full javascript reproduction of CVE-2026-63030 (author_exclude, author__not_in and misalignment between validations and matches)

Curated collection of injection payloads for web application security testing, covering SSTI, XXE, XSS, SSRF, SQLi, NoSQLi, LDAP, command injection,…

FreePBX Pre-Auth SQLi to RCE (CVE-2025-57819) — All-in-One Exploit

Exploit script for CVE-2026-41462, a critical unauthenticated stacked SQL injection in ProjeQtor ≤12.4.3. Creates admin accounts via crafted…

Proof-of-concept exploit for CVE-2021-27928, demonstrating remote code execution in MariaDB/MySQL via wsrep_provider eval injection, with msfvenom…

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

Exploit for CVE-2019-12086, a Jackson deserialization vulnerability, using a rogue MySQL server to read arbitrary files from vulnerable applications.

PoC exploit for CVE-2024-55963 targeting unauthenticated remote code execution on Appsmith Enterprise via misconfigured PostgreSQL. Supports…

Proof-of-concept exploit for pgAdmin 4 Import/Export RCE (CVE-2026-17566) abusing a backslash-escape mismatch to inject `\copy TO PROGRAM`, letting a…