
CVE-2025-24893
XWiki 15.10.11, 16.4.1 and 16.5.0RC1 Unauthenticated Remote code execution POC
exploitationpenetration-testingremote-access-tool+2

XWiki 15.10.11, 16.4.1 and 16.5.0RC1 Unauthenticated Remote code execution POC

SambaCry exploit and vulnerable container (CVE-2017-7494)

A self hosted virtual browser that runs in docker and uses WebRTC.

Linux eBPF backdoor over TCP. Spawn reverse shells, RCE, on prior privileged access. Less Honkin, More Tonkin.

Weaponized web shell

A PoC Java Stager which can download, compile, and execute a Java file in memory.

CVE-2025-66478 Proof of Concept

OSCP like CVE-2025-24893 exploit for Linux XWiki