
CVE-2023-27350
Unauthenticated remote command execution in Papercut service allows an attacker to execute commands due to improper access controls in the…

Unauthenticated remote command execution in Papercut service allows an attacker to execute commands due to improper access controls in the…

Another spring4shell (Spring core RCE) POC

A Rust implementation of the POC for the CVE-2009-2265 exploit, targeting Adobe ColdFusion 8.

bypass all stages of the password reset flow

WonderCMS Authenticated RCE - CVE-2023-41425

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected…

CVE 2021-44228 Proof-of-Concept. Log4Shell is an attack against Servers that uses vulnerable versions of Log4J.


The vulnerability allows an attacker with network access to an Erlang/OTP SSH server to execute arbitrary code without prior authentication.

A PoC for CVE-2025-24813

This script exploits the file upload feature in Pluck CMS v4.7.18 to upload a malicious PHP file, enabling remote access via a reverse shell. Once…

Exploitation of CVE-2023-44604. Using a Kali Linux VM (attacker) and a Debian 11 server VM (victim)


CVE-2023-28354

This vulnerability is of the "double-free" type, which occurs during the processing of key exchange (KEX) algorithms in OpenSSH. A "double-free"…

this is a metasploit exploit module for CVE-2024-25096 and CVE-2023-3452

Open Web Analytics 1.7.3 - Remote Code Execution