
CVE-2026-23744-script
Exploit script for CVE-2026-23744 targeting MCPJam Inspector (<=1.4.2) to achieve remote code execution via crafted HTTP requests.

Exploit script for CVE-2026-23744 targeting MCPJam Inspector (<=1.4.2) to achieve remote code execution via crafted HTTP requests.

Exploit for CVE-2021-3036, HTTP Smuggling + buffer overflow in PanOS 8.x

Proof-of-concept exploit for CVE-2021-41773, enabling remote code execution and CGI-bin path traversal on Apache HTTP Server 2.4.49. Includes…

Python-based scanner for detecting CVE-2021-41773 and CVE-2021-42013 path traversal and remote code execution vulnerabilities in Apache HTTP Server…

Proof-of-concept exploit for CVE-2025-55182, demonstrating remote code execution in React Server Components via unsafe request deserialization.…

Proof-of-concept exploit for a command injection vulnerability in Syrotech SY-GOPON-8OLT-L3, allowing arbitrary command execution via HTTP request…

Java-based exploit for Apache Struts2 CVE-2017-5638, executing arbitrary commands via crafted HTTP headers. Intended for authorized security…

C-based exploit for CVE-2017-17562 targeting GoAhead web server, enabling remote code execution via crafted HTTP requests.

Exploit for CVE-2019-0222 targeting Apache ActiveMQ 5.15.8, enabling remote code execution via crafted HTTP requests to the message broker's REST API.

Exploit for CrushFTP CVE-2025-31161 auth bypass: detects vulnerable targets, enumerates users, and creates unauthorized admin accounts through…

A proof of concept for CVE-2025-31161, using mangled HTTP header to perform unauthenticated impersonation of any user in Crush FTP server.

Rejetto http File Server 2.3.x (Reverse shell)

Python exploit for Apache HTTP Server path traversal (CVE-2021-41773 & CVE-2021-42013) enabling LFI and RCE via CGI. For authorized security testing…

Proof-of-concept for a stack-based buffer overflow in FortiWeb, demonstrating unauthenticated remote code execution via crafted HTTP requests when…

Exploit for CVE-2019-15107, a backdoor in Webmin versions 1.882-1.921, enabling unauthenticated remote command execution via crafted HTTP requests.

Python exploit for CVE-2021-42013, a path traversal and remote code execution vulnerability in Apache HTTP Server 2.4.49 and 2.4.50.

Shell script to exploit CVE-2021-41773, an Apache HTTP Server path traversal and remote code execution vulnerability.

Proof-of-concept exploit for CVE-2022-47522 demonstrating Wi-Fi frame interception via deauthentication attack and MAC address spoofing to capture…