
CVE-2025-5781
Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

🛡️ CVE-2026-64638 - WordPress Security Assessment Suite (CVSS 8.9) | WordPress 4.7.0-7.0.2 pentest toolkit. Includes vulnerability assessment &…

WordPress Core Pre-Auth RCE — Batch Route Confusion + SQL Injection

CVE-2026-60004 — Gitea <= 1.27.0 Pre-Auth RCE

Marimo exploit prior to 0.23.0. Pre-Auth RCE vulnerability via websocket endpoint : /terminal/ws.

Authenticated Blind OS Command Injection in ClearOS

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address

POCs to demonstrate CVE-2026-42167 in ProFTPD

pinky - The PHP mini RAT (Remote Administration Tool)

CVE-2018-19537

React2Shell Exploitation Tool (CVE-2025-55182)

CVE-2025-55182 React Server Components RCE - Go PoC

A sophisticated, wizard-driven Python exploit tool targeting CVE-2025-53770, a critical (CVSS 9.8) unauthenticated remote code execution (RCE)…

A comprehensive Python exploitation framework for testing and demonstrating CVE-2025-3248, a critical unauthenticated remote code execution…


CVE-2026-48908 - SP Page Builder Joomla Unauthenticated RCE

The objective is to conduct a full-scale security assessment of a WordPress-based web application, culminating in a complete server compromise. The…