
stylesmuggler
Python PoC reproducing CVE-2026-75650 StyleSmuggler, an unauthenticated Magento RCE via report poisoning and failed-payment rendering, with canary…

Python PoC reproducing CVE-2026-75650 StyleSmuggler, an unauthenticated Magento RCE via report poisoning and failed-payment rendering, with canary…

Proof-of-concept exploit for CVE-2026-34197, an RCE in Apache ActiveMQ via Jolokia's addNetworkConnector, with technical notes and reverse shell…

CVE-2026-33017 - Langflow Unauthenticated RCE Exploit

Proof-of-concept exploit for CVE-2026-23744, a remote code execution vulnerability in MCPJam inspector <=1.4.2, triggered via crafted HTTP requests…

Exploit for CVE-2026-23744, a remote code execution vulnerability in MCPJam Inspector, allowing attackers to execute arbitrary commands via crafted…

Java GUI tool for exploiting CVE-2026-21962, an unauthenticated RCE in Oracle WebLogic Proxy Plug-In, enabling multi-target command execution via…

PoC to tunnel the Meterpreter reverse HTTP shell over RDP Virtual Channels

Python 2.7

Peyara Remote Mouse Unauthenticated Arbitrary File Upload


Python backdoor that uses http post/get requests to communicate

Remote Administration Toolkit (or Trojan) for POSiX (Linux/Unix) system working as a Web Service

pinky - The PHP mini RAT (Remote Administration Tool)

Exploit script for Apache HTTP Server 2.4.49/2.4.50 path traversal and remote code execution (CVE-2021-41773). Includes Docker-based reproduction…

RCE on Apache Solr using deserialization of untrusted data via jmx.serviceUrl

Another spring4shell (Spring core RCE) POC

A Rust implementation of the CVE-2014-6287 exploit targeting Rejetto HTTP File Server (HFS) versions 2.3x before 2.3c.

This repository contains Detailed explanation and working poc for Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution.