
exploit-CVE-2017-7494
SambaCry exploit and vulnerable container (CVE-2017-7494)

SambaCry exploit and vulnerable container (CVE-2017-7494)

Exploit for CVE-2023-46604 in Apache ActiveMQ, enabling remote code execution via crafted XML payloads and reverse shell establishment.

Python script exploiting CVE-2019-8943 for authenticated remote code execution on WordPress, deploying a PHP backdoor for post-exploitation access.

Proof-of-concept exploit for CVE-2026-75430, achieving unauthenticated remote code execution on PowerJob Worker via arbitrary JAR loading through the…

A self hosted virtual browser that runs in docker and uses WebRTC.

Proof-of-concept exploit for CVE-2025-1974 (IngressNightmare) targeting Kubernetes Ingress-NGINX Admission Controller to achieve remote code…

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

Gorsair gives root access on remote docker containers that expose their APIs

Exploit for Mass Remote Code Execution on GPON home routers (CVE-2018-10562) obtained from Shodan.

Exploit of CVE-2019-8942 and CVE-2019-8943

Reproduces CVE-2020-15778 SCP command injection exploit with Docker-based client-server setup for testing remote code execution and reverse shell…

Python exploit for CVE-2021-22205, a remote command execution in GitLab CE/EE via image file parsing. Supports vulnerability checking, batch…

PoC exploit for CVE-2023-46604 targeting Apache ActiveMQ, delivering a reverse shell via crafted XML payload over HTTP.

CVE-2022-0824, CVE-2022-0829, File Manger privilege exploit

Reproduction and root cause analysis of CVE-2026-39987 Marimo pre-auth WebSocket RCE in a local Docker lab.

Authenticated RCE exploit for MotionEye <= 0.43.1b4 via client-side validation bypass on the image_file_name field. Includes reverse shell payload…