
CVE-2025-6934-PoC
CVE-2025-6934 Exploit Tool Unauthenticated Administrator Account Creation in WordPress Plugin Opal Estate Pro

CVE-2025-6934 Exploit Tool Unauthenticated Administrator Account Creation in WordPress Plugin Opal Estate Pro

CVE-2019-6340 Drupal 8.6.9 REST Auth Bypass examples

Python-based exploit for Hotel Druid 3.0.3 Remote Code Execution (CVE-2022-22909). Injects PHP payloads via room names to achieve command execution…

Statamic CMS versions <4.33.0 vulnerable to "Remote Code Execution"

Exploit for CrushFTP CVE-2025-31161 auth bypass: detects vulnerable targets, enumerates users, and creates unauthorized admin accounts through…

CVE-2018-10933 very simple POC

A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass

BeyondCart Connector <= 2.1.0 - Missing Configuration of JWT Secret to Unauthenticated Privilege Escalation

Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).

Spring4Shell Proof Of Concept/And vulnerable application CVE-2022-22965

Unauthenticated remote code execution exploit for Oracle WebLogic CVE-2017-10271. Provides XML payload and endpoint list for penetration testing of…

Proof-of-concept exploit for CVE-2020-11651 and CVE-2020-11652 enabling remote command execution and filesystem access on vulnerable SaltStack…

Example Vulnerable .NET HTTP Remoting

Exploit script for CVE-2025-55182 that deploys a Godzilla memory shell on vulnerable web servers, with support for proxy and encoding options.

Tool to generate csrf payloads based on vulnerable requests

SMTP vulnerability scanner and exploit script that checks for CVE-2024-45519 and establishes a reverse shell on vulnerable servers.

Abuse Log4J CVE-2021-44228 to patch CVE-2021-44228 in vulnerable Minecraft game sessions to prevent exploitation in the session :)

Proof-of-concept exploit for CVE-2022-22963 (Spring4Shell) with a vulnerable Docker container and curl-based remote code execution via Spring Cloud…