
cve-2019-18683
Proof-of-concept exploit for CVE-2019-18683, a Linux kernel vulnerability enabling local privilege escalation through a race condition in the virtual…

Proof-of-concept exploit for CVE-2019-18683, a Linux kernel vulnerability enabling local privilege escalation through a race condition in the virtual…

FreePBX Pre-Auth SQLi to RCE (CVE-2025-57819) — All-in-One Exploit

Curated collection of validated Joomla exploit artifacts with Docker lab environments. Includes RCE, SQLi, XSS, and privilege escalation scripts…

Technical advisory and proof-of-concept for CVE-2024-13985, a critical unauthenticated remote code execution vulnerability in Dahua EIMS via command…

working exploit for the old cve-2021-21425 grav cms 1.7.10 vuln

Unauthenticated Remote Code Execution (RCE) vulnerability in the JCE (Joomla Content Editor) extension for Joomla

Proof-of-concept exploit for CVE-2025-10307 demonstrating arbitrary file deletion via path traversal in the WordPress Backuply plugin's tar_file…

used to generate a valid attack chain to exploit CVE-2017-11774 tied to iranian apt only reasearch poc dont use for harm please

Exploit for the CVE-2026-8181 - Burst Statistics WordPress Plugin Authentication Bypass

Proof-of-concept exploit for CVE-2021-21148, a Google Chrome vulnerability. Executes the exploit with a single command for testing and validation…

A totally unauthenticated file-upload endpoint in Visual Composer lets anyone drop arbitrary files (e.g., a JSP web-shell) onto the server.

PowerShell script for local privilege escalation on Windows via the PrintNightmare vulnerability (CVE-2021-1675), adding a local admin user or…

Proof-of-concept exploit for CVE-2026-1560, an authenticated remote code execution vulnerability in Lazy Blocks WordPress plugin, allowing…

Microsoft just released emergency patches for CVE-2026-21509, a zero-day in the Office Suite that bypasses OLE/COM mitigations when a user simply…

Proof-of-concept exploit for CVE-2026-24126, an arbitrary file read in Weblate via SSH host argument injection, allowing authenticated admins to read…

Proof-of-concept exploit for CVE-2025-6264 in Velociraptor, demonstrating privilege escalation via missing permission checks to redirect clients to a…

Provides working proof-of-concept exploits and detailed analysis for three critical Apache Camel vulnerabilities, including CoAP header injection and…

Exploit for CVE-2026-33017, an unauthenticated RCE in Langflow 1.8.1 via the build_public_tmp endpoint, enabling Python code injection through…