
CVE-2022-35914-RCE
PoC exploit for CVE-2022-35914 — GLPI v.10.0.2 htmLawed command injection, command execution, and reverse shell support.

PoC exploit for CVE-2022-35914 — GLPI v.10.0.2 htmLawed command injection, command execution, and reverse shell support.

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

Python-based exploit for Tongda OA remote code execution by chaining file inclusion and upload vulnerabilities to obtain a reverse shell.

Exploit tool for Redis 4.x/5.x that achieves remote code execution by loading a custom RedisModule (exp.so) through a rogue server, enabling…

Single-file PHP web shell for remote command execution with file upload/download and command history, designed for penetration testing of PHP…

Java-based Oracle database exploitation tool for command execution, file management, and reverse shell via PL/SQL functions.

Exploitation tool for CGI shell upload vulnerabilities. Uploads a web shell to vulnerable CGI endpoints, granting remote command execution on the…

Exploit toolkit for CVE-2026-61511 targeting vBulletin pre-auth RCE, featuring multi-endpoint exploitation, WAF bypass via PHPFuck, and…

Node.js exploit script that achieves authenticated remote command execution on vulnerable Webmin instances (CVE-2019-12840) for penetration testing.

Proof-of-concept for CVE-2025-8714, demonstrating remote code execution in PostgreSQL via malicious pg_dump flat-format dumps, with automated reverse…

Proof-of-concept exploit for authenticated remote code execution in PostgreSQL 9.6.1, demonstrating how misconfigured databases can be leveraged for…

💉 Blind SQL Injection → RCE exploit for Control Web Panel (CWP) ≤ 0.9.8.1224 — userRes POST → INTO DUMPFILE → cwpsvc shell

Exploit script for CVE-2021-29442 targeting Nacos Derby RCE via SQL injection. Automates unauthorized access and remote command execution on…

Proof-of-concept exploit for CVE-2019-9193, enabling remote code execution in PostgreSQL via the COPY TO/FROM PROGRAM feature, targeting superuser…

Directory transversal to remote code execution

CVE-2019–9193 - PostgreSQL 9.3-12.3 Authenticated Remote Code Execution

Proof-of-concept exploit for CVE-2022-24706 targeting Apache CouchDB 3.2.1 and below. Demonstrates remote command execution via Erlang Distribution…

Step-by-step guide to exploit MariaDB UDF vulnerability for authenticated code execution, including DLL upload, function creation, and reverse shell…