
cve-2022-42475-poc
Proof of Concept (PoC) for research and controlled laboratory validation of CVE-2022-42475, a critical heap-based buffer overflow vulnerability…

Proof of Concept (PoC) for research and controlled laboratory validation of CVE-2022-42475, a critical heap-based buffer overflow vulnerability…

Detection artifact generator for Ivanti Sentry authentication bypass and RCE vulnerabilities (CVE-2026-10520, CVE-2026-10523). Scans single or…

Simple PHP reverse shell script for establishing remote command execution on target systems. Ideal for penetration testing and security assessments.

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

Full walkthrough of HTB's Reactor machine — exploit CVE-2025-55182 to gain a shell, then get root via an exposed Node.js debugger. Step-by-step with…

A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go

Minimal PHP web shell with password-protected remote command execution, file upload/fetch, for penetration testing on Unix and Windows targets.

PoC toolkit for exploiting Cisco IMC RCE CVE-2026-20200

Automated PoC for Gitea pre-auth RCE via diffpatch API collision; plants a git hook and provides an interactive API-driven shell for authorized…

Exploits CVE-2026-39987, a pre-auth RCE in Marimo <0.23.0, via the /terminal/ws WebSocket endpoint to provide an interactive shell and file transfer.

Automated PoC exploit for Gitea/Forgejo template symlink RCE that injects an SSH key via variable expansion, yielding a remote shell as the git…

Marimo exploit prior to 0.23.0. Pre-Auth RCE vulnerability via websocket endpoint : /terminal/ws.

CVE-2023-52251 There is a Remote Code Execution vulnerability provectus/kafka-ui.

Authenticated RCE exploit for WBCE CMS <= 1.6.3 that creates a malicious module zip with a PHP reverse shell and netcat listener.

Hooked browser communication over MQTT

Exploit script for CVE-2024-50498 code injection in WordPress WP Query Console that checks vulnerability and delivers a reverse shell.

PHP script that establishes a reverse shell from a target server to the attacker's machine, enabling remote command execution and post-exploitation…