
cve-2023-1874
Python exploit script for CVE-2023-1874, a privilege escalation vulnerability in the WP Data Access WordPress plugin. Enables authenticated…

Python exploit script for CVE-2023-1874, a privilege escalation vulnerability in the WP Data Access WordPress plugin. Enables authenticated…

Python exploit script for CVE-2020-14321, enabling privilege escalation from teacher to manager in Moodle via cookie-based session hijacking and role…

☣️ This repository contains the description and a proof of concept for CVE-2024-34313

Automated exploitation framework for CVE-2025-55182 (Next.js RCE) with subdomain enumeration, vulnerability scanning, payload generation, and…

Proof-of-concept for CVE-2025-65094: privilege escalation via IDOR in WBCE CMS. Demonstrates group ID manipulation to gain admin access, with…

Short Python script for exploiting CVE-2025–24000 based on this blog post: https://medium.com/@security_56355/from-subscriber-to-admin-reproducing-cve…

a PoC for the Nagios CVE-2019-15949 rce in python

The code for personally reproducing the corresponding vulnerability

Missing Authorization / Broken Access Control in Plugin - MyRewards – Loyalty Points and Rewards for WooCommerce

Educational Proof-of-Concept for the CVE-2022-30190 (Follina) vulnerability.

The Real Estate 7 WordPress theme is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.2. This makes it possible for…

Exploit for CVE-2014-4210 targeting WebLogic deserialization, with post-exploitation features including ransomware deployment, C2 integration, and…

Quick mitigation and patch script for CVE-2026-31431 (Copy Fail) on Ubuntu/Debian VPS

Proof-of-concept exploit for a mass assignment privilege escalation vulnerability in Camaleon CMS < 2.9.1. Authenticated low-privilege users can…

A number of exploits and tools I've written for CVEs accredited to Marshall Whittaker/oxagast

Python exploit script for CVE-2025-2304, a mass assignment privilege escalation in Camaleon CMS. Automates CSRF token parsing and role parameter…

Multi-threaded exploit for CVE-2025-2563 targeting unauthenticated privilege escalation in the WordPress User Registration & Membership plugin.…

Unauthenticated Privilege Escalation CVE-2026-9018: Easy Elements for Elementor