
POC-CVE-2025-68613
Proof-of-concept exploit for CVE-2025-68613, an authenticated remote code execution vulnerability in N8N. Executes arbitrary bash commands on…

Proof-of-concept exploit for CVE-2025-68613, an authenticated remote code execution vulnerability in N8N. Executes arbitrary bash commands on…

A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go

A Magisk module that simplifies running the Frida server on Android, with easy management commands to download specific versions, enable or disable…

Java-based proof-of-concept exploit for CVE-2026-22812, a remote code execution vulnerability in OpenCode, demonstrating exploitation with a simple…

Proof-of-concept exploit for CVE-2026-23744, demonstrating unauthenticated remote code execution in MCPJam Inspector versions up to 1.4.2 via crafted…

Exploit for CVE-2025-34085

Unauthenticated authentication bypass to RCE exploit for CVE-2024-10924. Abuses an authentication and 2FA bypass in the Really Simple Security…

Bash-based scanner for detecting and exploiting CVE-2025-55182 (React Server Components RCE) in Next.js applications. Supports custom command…

Scanner and educational guide for CVE-2025-49844 (RediShell), a Redis Lua scripting use-after-free vulnerability. Checks Redis servers for exposure,…

C# tool that builds a GZipped, Base64-encoded .NET DataSet payload using LosFormatter to reproduce the SharePoint deserialization RCE chain…

Multi-target unauthenticated RCE scanner for CVE-2025-34085 affecting WordPress Simple File List plugin. Uploads, renames, and triggers PHP webshells…

Simple File List – Unauthenticated RCE Exploit (CVE-2025-34085)

A simple C-based vulnerability in Webmin versions 1.890 to 1.920

Here is a simple but effective exploit for CVE-2025-29927.

A real exploit for BitBucket RCE CVE-2022-36804

it is script designed to exploit certain vulnerabilities in routers by sending payloads through SNMP (Simple Network Management Protocol). The script…

Python exploit script for CVE-2024-41628, a Local File Inclusion vulnerability in ClusterControl CMON API (ports 9500/9501). Retrieves arbitrary…

Chain CVE-2019-11408 – XSS in operator panel and CVE-2019-11409 – Command injection in operator panel.