
Ashwesker-CVE-2026-21962
Exploit PoC and Nuclei template for CVE-2026-21962, a critical unauthenticated remote code execution in Oracle HTTP Server and WebLogic Proxy…

Exploit PoC and Nuclei template for CVE-2026-21962, a critical unauthenticated remote code execution in Oracle HTTP Server and WebLogic Proxy…

Automates CVE-2024-23692 exploitation against unpatched Rejetto HFS with an in-memory PowerShell reverse shell, HTTP payload staging, and AV/EDR…

Proof-of-concept exploit for CVE-2026-19286 in Langflow, allowing authenticated remote command execution via crafted HTTP requests.

Proof-of-concept exploit for CVE-2021-40346, an integer overflow in HAProxy enabling HTTP request smuggling and potential access control bypass.

Proof-of-concept exploit for CVE-2022-26377, an AJP smuggling vulnerability that poisons the HTTP response queue of IBM QRadar with a stored redirect.

Exploit CVE-2024-43468 and CVE-2025-59213 to implant a controlled backdoor into SCCM Management Point's SQL stored procedure, enabling remote SQL…

Python exploit for CVE-2026-41940, a critical CRLF injection in cPanel/WHM cpsrvd that bypasses authentication and 2FA, granting root-level access…

Exploit for CVE-2020-14882 targeting Oracle WebLogic Server versions 10 and 12, enabling unauthenticated remote code execution via crafted HTTP…

Python exploit script for CVE-2020-14882 targeting Oracle WebLogic Server. Executes remote commands via crafted HTTP requests to unauthenticated…

Metasploit module that exploits Apache HTTP Server SSRF (CVE-2024-38472) on Windows to reach internal services and achieve remote code execution.

Exploit for CVE-2025-61882, a critical pre-auth RCE in Oracle E-Business Suite. Combines SSRF, CRLF injection, HTTP smuggling, and XSLT injection for…

Python exploit script for CVE-2021-21425 targeting Grav CMS admin panel, delivering a reverse shell via HTTP POST request with configurable LHOST and…

Exploit for OpenAM pre-auth RCE (CVE-2026-33439) using a Java deserialization gadget chain to execute commands and return output directly in the HTTP…

Proof-of-concept exploit for CVE-2026-23744, demonstrating unauthenticated remote code execution in MCPJam Inspector versions up to 1.4.2 via crafted…

Proof-of-concept exploit for CVE-2025-49002, a remote code execution vulnerability in DataEase via PostgreSQL JDBC bypass, including a crafted HTTP…

Exploit for CVE-2021-25646 Apache Druid RCE via crafted HTTP POST request to the sampler endpoint, with embedded payload delivery and Snort detection…

Proof-of-concept exploit for CVE-2025-9074 enabling Docker Desktop API escape via raw HTTP requests. Provides an emulated interactive shell inside a…

Nuclei template for detecting CVE-2026-33017, an unauthenticated remote code execution vulnerability in Langflow ≤ 1.8.2. Performs non-destructive…