
CVE-2025-5781
Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

🛡️ CVE-2026-64638 - WordPress Security Assessment Suite (CVSS 8.9) | WordPress 4.7.0-7.0.2 pentest toolkit. Includes vulnerability assessment &…

WordPress Core Pre-Auth RCE — Batch Route Confusion + SQL Injection

CVE-2026-60004 — Gitea <= 1.27.0 Pre-Auth RCE

Marimo exploit prior to 0.23.0. Pre-Auth RCE vulnerability via websocket endpoint : /terminal/ws.

Authenticated Blind OS Command Injection in ClearOS

CVE-2026-48908 - SP Page Builder Joomla Unauthenticated RCE


POCs to demonstrate CVE-2026-42167 in ProFTPD

React2Shell Exploitation Tool (CVE-2025-55182)

CVE-2025-55182 React Server Components RCE - Go PoC

A comprehensive Python exploitation framework for testing and demonstrating CVE-2025-3248, a critical unauthenticated remote code execution…

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address

The objective is to conduct a full-scale security assessment of a WordPress-based web application, culminating in a complete server compromise. The…

Research Objective: To conduct a comprehensive analysis and successful exploitation of a Remote Code Execution (RCE) vulnerability in Webmin version…

A sophisticated, wizard-driven Python exploit tool targeting CVE-2025-53770, a critical (CVSS 9.8) unauthenticated remote code execution (RCE)…

DeimosC2 is a Golang command and control framework for post-exploitation.
