
CVE-2015-3224
Metasploit module for CVE-2015-3224 that enables arbitrary command execution in Ruby on Rails Web Console by extending the original RCE module with…

Metasploit module for CVE-2015-3224 that enables arbitrary command execution in Ruby on Rails Web Console by extending the original RCE module with…

Proof-of-concept exploit for CVE-2016-2098, demonstrating remote code execution via template injection in Rails 4.2.5.1 view rendering.

Exploit shell for CVE-2012-2688, providing remote code execution against vulnerable Ruby on Rails applications via a crafted HTTP request.

Proof-of-concept exploit script for CVE-2016-2098, a remote code execution vulnerability in Ruby on Rails' Action Pack render method. Executes…

Proof-of-concept exploit for CVE-2016-0752, a remote code execution vulnerability in Ruby on Rails via dynamic render paths. Includes vulnerable app,…

Proof of concept for CVE-2016-2098, demonstrating remote code execution via template injection in Rails 4.2.5.1 with curl commands and reverse shell…

Mountable Rails engine providing 24+ cybersecurity escape room scenarios with randomized passwords, JIT-compiled NPC dialogue, and RESTful API for…

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

SQL injection exploit for Joomla JCK Editor 6.4.4 (CVE-2018-17254) that dumps admin credentials and optionally uploads a PHP RCE shell via stacked…

Proof-of-concept exploit for CVE-2024-55968, a macOS local privilege escalation via an unvalidated XPC helper in DTEX Event Forwarder, abusing the…

Proof-of-concept exploit for a stored XSS vulnerability in Ghost CMS (CVE-2025-66849) enabling privilege escalation from Contributor to Owner via…

Exploit for CVE-2026-5203 in CMS Made Simple, leveraging path traversal and arbitrary file upload to achieve remote code execution with an…

Proof-of-concept exploit for CVE-2025-56499, demonstrating arbitrary file read via missing path validation in mihomo's rule-provider configuration,…

Alternative payloads for InvokeAI RCE (CVE-2024-12029) including reverse shells, callback tests, and SSH injection bypasses for pickle…

Python proof-of-concept for authenticated path traversal (CWE-22) in Camaleon CMS, enabling arbitrary file read via crafted requests to…

Proof-of-concept exploit for CVE-2025-15556, demonstrating update integrity bypass in Notepad++ WinGUp updater via MITM proxy or DNS spoofing,…

Proof‑of‑concept exploit for CVE‑2025‑7840 that injects malicious payloads into the Firstname parameter of a reservation form to trigger XSS

A library for detecting known secrets across many web frameworks