
Spring4Shell-POC
Reproduces the Spring4Shell (CVE-2022-22965) remote code execution vulnerability with a Python exploit script, deploying a JSP webshell on Apache…

Reproduces the Spring4Shell (CVE-2022-22965) remote code execution vulnerability with a Python exploit script, deploying a JSP webshell on Apache…

Automated Mass Exploiter

CVE-2022-42889 (a.k.a. Text4Shell) RCE Proof of Concept

A honeypot for the Log4Shell vulnerability (CVE-2021-44228).

Post-authentication RCE exploit for Roundcube ≤ 1.6.10 via PHP object deserialization, with Docker-based lab setup and technical writeup for security…

Python script to exploit CVE-2023-38646 Metabase Pre-Auth RCE via SQL injection

Python-based exploit for CVE-2025-55182 (React Server Components RCE) with interactive shell, reverse shell, batch scanning, and Docker-based…

Proof-of-concept lab for CVE-2017-5941 node-serialize untrusted deserialization RCE. Includes POST and cookie-based exploit vectors with Docker…


CVE-2022-22965 proof of concept

This project demonstrates a proof-of-concept exploit for CVE-2022-30190, also known as "Follina"—a critical remote code execution vulnerability…

Exploit for CVE-2025-55182 targeting Next.js React Server Components via prototype pollution, enabling remote code execution with command execution…

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

A simple Log4j PoC written in Go

XLL Phishing Tradecraft

A modular framework for benchmarking LLMs and agentic strategies on security challenges across HackTheBox, TryHackMe, PortSwigger Labs, Cybench,…

PoC for CVE-2026-66066 in Ruby on Rails

CVE-2023-50164 PoC Application & Exploit script