
CVE-2021-44228_PoC
Python proof-of-concept for CVE-2021-44228 (Log4Shell) that automates exploitation via a crafted Java payload, with argparse options for customizable…

Python proof-of-concept for CVE-2021-44228 (Log4Shell) that automates exploitation via a crafted Java payload, with argparse options for customizable…

a exp for cve-2018-9948/9958 , current shellcode called win-calc

Exploit for CVE-2020-15778(OpenSSH vul)

Python exploit for CVE-2020-14008 in ManageEngine Applications Manager delivering a SYSTEM-level reverse shell via authenticated remote code…

Exploit script chaining CVE-2026-53595 (anonymous account takeover) and CVE-2026-53593 (.pht upload) for unauthenticated remote code execution on…

Python script to exploit CVE-2023-38646 Metabase Pre-Auth RCE via SQL injection

PoC of Remote Command Execution via Log injection on SAP NetWeaver AS JAVA CRM

Apache struts struts 2 048, CVE-2017-9791.

Dynamically extracts fresh syscall stubs from ntdll.dll to evade signature-based detection, with a shellcode execution template for Nim-based…

Simple exploit for Wing FTP Server RCE (CVE-2025-47812) to run commands and get a reverse shell. For educational use only.

exp for cve-2014-7911 which can get system privillage

PowerShell-based reverse shell with background task execution, file transfer, and dual persistence mechanisms via registry and startup folder for red…

PoC payload generator for CVE-2022-44268 ImageMagick arbitrary file read vulnerability. Demonstrates exploitation via crafted PNG files for…

### This module requires Metasploit: https://metasploit.com/download# Current source: https://github.com/rapid7/metasploit-framework##class…

Automatically spawn a reverse shell fully interactive for Linux or Windows victim

Proof-of-concept exploit for CVE-2018-6574, demonstrating remote command execution in Go's go get command via malicious compiler plugins during…

Python exploit for CVE-2025-24801 achieving Remote Code Execution via Local File Inclusion in GLPI 10.0.17. Includes command execution mode for…

Proof-of-concept exploit for CVE-2018-6574, a remote code execution vulnerability in Go's 'go get' command via malicious package import paths.