
CVE-2026-57517
💉 Blind SQL Injection → RCE exploit for Control Web Panel (CWP) ≤ 0.9.8.1224 — userRes POST → INTO DUMPFILE → cwpsvc shell

💉 Blind SQL Injection → RCE exploit for Control Web Panel (CWP) ≤ 0.9.8.1224 — userRes POST → INTO DUMPFILE → cwpsvc shell

PoC for Blind RCE for CVE-2022-25765 (Tested in HTB - Precious Machine)

Exploit for CVE-2021-22911: pre-auth blind NoSQL injection in Rocket Chat 3.12.1 enabling account takeover and remote code execution via webhook…

Pre-Auth Blind NoSQL Injection leading to Remote Code Execution in Rocket Chat 3.12.1

Unauthenticated RCE exploit for GeoServer (CVE-2024-36401) via OGC filter XPath injection. Supports reverse shell and blind command execution with…

CVE-2019-18818/19606 Strapi RCE

Exploit for CVE-2017-12945.

Go PoC for CVE-2025-32433 — unauthenticated RCE in Erlang/OTP SSH.

Proof-of-concept exploit for CVE-2026-54806: unauthenticated PHP object injection in WP Activity Log plugin enabling blind RCE via User-Agent header.…

Python exploit for CVE-2022-0944 enabling blind remote code execution in SQLPad through the /api/test-connection endpoint with netcat callback.

Exploit for CVE-2017-6079 blind command injection in Edgewater Edgemarc devices; reads remote files and uploads/executes ELF payloads via hidden…

JSshell - JavaScript reverse/remote shell