
React2Shell
R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

Authenticated arbitrary file read exploit for the File Away WordPress plugin (CVE-2025-2539). Includes PoC, attack flow, detection signatures, and…

Manual poc for CVE-2025-2304

CVE-2025-54914 exposes a critical flaw in Azure Networking that allows attackers to escalate privileges and control routing across subnets. The…

Exploit for CVE-2025-2304 | Camaleon CMS versions < 2.9.1

Exploit for CVE-2025-2304

An advanced exploit for Microsoft Exchange Server (CVE-2021-26855, CVE-2021-27065) enhanced with Convergent Time Theory principles, achieving…

Authenticated API Key Exposure in Nagios Log Server 2024R1.3.1

Proof of Concept exploits for CVE-2025-34322 and CVE-2025-34323 in Nagios Log Server

PoC for CVE-2025-2304 Privilege Escalation in the Camaleon CMS

Appy Pie Connect for WooCommerce <= 1.1.2 - Missing Authorization to Unauthenticated Privilege Escalation

A self-hosted vulnerable Next.js environment running on Docker for simulating CVE-2025-55182. Built for educational security research and CTF…

Proof-of-concept for CVE-2025-52289: a broken access control vulnerability in MagnusBilling allowing unauthenticated privilege escalation from…

Post-authentication remote code execution exploit for Microsoft Exchange Server (CVE-2022-41082) with a PowerShell privilege escalation script for…

Proof-of-concept exploit for CVE-2022-24644, demonstrating unauthenticated remote code execution via DNS spoofing against KeyMouse Windows 3.08…

Proof-of-concept exploit for CVE-2025-46157: Remote code execution via insecure file upload in Timetrax V1 Attendance module, with EfsPotato-based…

WordPress Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Plugin <= 2.4.37 is vulnerable to Privilege Escalation

Intentionally vulnerable PHP app with Nginx/PHP-FPM setup for reproducing CVE-2019-11043, including Docker and Kubernetes deployment,…