
EternalBlue-Exploit-Demonstration
Educational lab demonstrating EternalBlue (MS17-010) exploitation against Windows 7 using Metasploit, including post-exploitation, WannaCry…

Educational lab demonstrating EternalBlue (MS17-010) exploitation against Windows 7 using Metasploit, including post-exploitation, WannaCry…

WordPress CMP – Coming Soon & Maintenance plugin <= 4.1.13 - Remote Code Execution (RCE) vulnerability

Proof-of-concept exploit for CVE-2024-5084 (Hash Form WordPress plugin) demonstrating unauthenticated file upload to RCE. Designed for educational…

This script exploits Remote Code Execution vulnerability in Pterodactyl Panel < 1.11.11

Nuclei template providing a proof-of-concept for CVE-2024-4577, a PHP CGI argument injection vulnerability, enabling automated detection and testing.

Proof-of-concept exploit for the Log4Shell vulnerability (CVE-2021-44228) in Apache Log4j, demonstrating remote code execution via JNDI injection.

cve-2022-29464 EXP

(CVE-2023-4220) Chamilo LMS Unauthenticated Big Upload File Remote Code Execution

Proof-of-concept for arbitrary file upload RCE in django-summernote when Pillow is missing. Exploits CWE-434 to upload a web shell.

Proof-of-Concept exploit for CVE-2025-9074

CVE-2017-9805: Apache Struts 2 S2-052 RCE Exploit - PoC for Harvard University (OTD)

Exploitation toolkit for CVE-2025-59287 RCE in WSUS. Includes AES payload encryption and an exploitation module for authorized penetration testing.

Metabase postgres (org.h2.Driver) RCE without INIT

monstra_cms-3.0.4-上传getshell CVE-2018-17418

Proof-of-concept exploit for CVE-2025-24813, achieving remote code execution on Apache Tomcat via session deserialization and partial PUT requests.

CVE-2023-23397 C# PoC

PoC for CVE-2025-22131

Xss injection, WonderCMS 3.2.0 -3.4.2