
CVE-2021-44077
Proof-of-concept exploit for PreAuth RCE in ManageEngine ServiceDesk Plus (CVE-2021-44077). Uploads and executes arbitrary Windows executables on…

Proof-of-concept exploit for PreAuth RCE in ManageEngine ServiceDesk Plus (CVE-2021-44077). Uploads and executes arbitrary Windows executables on…

An OWASP-aligned intentionally vulnerable platform for learning and testing AI, LLM, RAG, MCP, and Agentic AI security.

Advanced PoC & Research for CVE-2026-0828 (Safetica) and CVE-2025-7771 (ThrottleStop). Analysis of BYOVD (Bring Your Own Vulnerable Driver) TTPs for…

Exploit for PHP CGI Argument Injection (CVE-2024-4577) enabling remote code execution on vulnerable Windows servers running Apache and PHP-CGI.…

Python-based detection artifact generator for Ivanti Sentry authentication bypass and remote code execution vulnerabilities (CVE-2026-10520,…

Python exploit for CVE-2021-26084 targeting Confluence Server pre-authentication remote code execution via OGNL injection. Executes arbitrary…

Local privilege escalation exploit for CVE-2018-14665 targeting X.Org Server on OpenBSD and Linux. Provides a proof-of-concept script to gain root…

Proof-of-concept exploit for CVE-2024-8190, an authenticated command injection vulnerability in Ivanti Cloud Service Appliance, enabling remote…

Detection artifact generator for CVE-2025-52691, a pre-auth path traversal leading to unauthenticated RCE in SmarterMail. Probes vulnerable builds by…

WP2Shell - CVE-2026-63030 / CVE-2026-60137 This tool exploits a critical SQL injection vulnerability in the WordPress REST API `/wp-json/batch/v1`…

Perl-based exploit for CVE-2014-7236 targeting TWiki code execution vulnerability. Enables remote command injection on vulnerable TWiki installations…

Exploit for CVE-2023-52271 in C++. The code exploits the vulnerable driver wsftprm.sys kernel driver 2.0.0.0, which allows kernel-level access to…

PoC exploit for CVE-2024-7029 in AvTech devices. Scans for vulnerable targets and provides an interactive remote shell for command execution with…

Shell-based remote code execution exploit targeting CVE-2019-19781 in Citrix Application Delivery Controller and Citrix Gateway. Executes arbitrary…

Remote Code Execution exploit for WSO2 products targeting CVE-2022-29464, enabling unauthenticated attackers to execute arbitrary commands on…

Exploit CVE-2025-49844 Redis Lua UAF vulnerability to execute arbitrary shellcode and establish persistent backdoor access on vulnerable Redis…

Proof-of-concept exploit for CVE-2022-29464 enabling unrestricted file upload and remote code execution on vulnerable WSO2 products, with a custom…