
Magneto-PolyShell
Magento 2 Unauthenticated RCE Exploit – Uploads a PHP webshell via GraphQL product lookup + guest cart custom options. Multi‑threaded, auto‑detects…

Magento 2 Unauthenticated RCE Exploit – Uploads a PHP webshell via GraphQL product lookup + guest cart custom options. Multi‑threaded, auto‑detects…

PoC for CVE-2025-56399 - Unrestricted File Upload leading to RCE in alexusmai/laravel-file-manager (≤3.3.1). Automates detection, CSRF extraction,…

Super Forms Unauthenticated File Upload RCE | CVSS 9.8

A very simple MSDT "Follina" exploit **patched**

Exploit loader for Remote Code Execution w/ Payload on GPON Home Gateway devices (CVE-2018-10562) written in Python.

Takeover of Oracle WebLogic Server

WordPress Hash Form – Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

POC to replicate the full 'Follina' Office RCE vulnerability for testing purposes

BurpSuite plugin for HTTP packet analysis and fuzzing dictionary generation. Extracts parameters, paths, and files from requests, counts frequency,…

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

Python exploit for the CVE-2021-22204 vulnerability in Exiftool

Ghostscript command injection vulnerability PoC (CVE-2023-36664)

POC Exploit for Apache Tomcat 7.0.x CVE-2017-12615 PUT JSP vulnerability.

React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local…

A honeypot for the Log4Shell vulnerability (CVE-2021-44228).

Atlassian JIRA Template injection vulnerability RCE

Exploit the vulnerability to execute the calculator