
CVE-2026-39987
Exploit for Marimo pre-auth RCE via terminal WebSocket, providing command execution, interactive PTY shell, and reverse shell capabilities for…

Exploit for Marimo pre-auth RCE via terminal WebSocket, providing command execution, interactive PTY shell, and reverse shell capabilities for…

Exploit for CVE-2026-33017 — Unauthenticated RCE in Langflow <= 1.8.2 via exec() in flow build endpoint

Detection artifact generator for Ivanti Sentry authentication bypass and RCE vulnerabilities (CVE-2026-10520, CVE-2026-10523). Scans single or…

Exploit for CVE-2021-40539: RCE in Zoho ManageEngine ADSelfService Plus. Includes detection script, Fofa search syntax, and webshell deployment for…

POC - Unauthenticated RCE Flaw in Rejetto HTTP File Server - CVE-2024-23692

Python-based proof-of-concept exploit for CVE-2022-32548, an unauthenticated remote code execution vulnerability in DrayTek routers via buffer…

CVE-2025-3248 — Langflow RCE Exploit

Proof-of-concept exploit for CVE-2025-31324, a remote code execution vulnerability in SAP NetWeaver, with Shodan dorks for target discovery and…

CVE-2025-27480 exposes a buffer overflow in OpenSSH 8.9p1 via a malformed SSH_USERAUTH packet. Attackers can inject shellcode and gain SYSTEM-level…

CVE-2021-40539:ADSelfService Plus RCE漏洞

Proof-of-concept exploit for CVE-2023-36845 enabling unauthenticated remote code execution on Juniper SRX firewalls and EX switches via PHP…

This exploit was created to exploit an XXE (XML External Entity). Through it, I read the backend code of the web service and found an endpoint where…

PoC exploit and NSE scanner for CVE-2021-21985, a vCenter Server RCE vulnerability in the vSAN Health Check plugin, with manual exploitation steps…

CVE-2015-3224 Exploit - Rails Web Console RCE

Source code for a BPFDoor backdoor controller supporting TCP, UDP, ICMP, and HTTPS covert communication channels with magic packet activation,…

Proof-of-concept exploit for CVE-2020-0609 that crashes a Remote Desktop Gateway server by sending a crafted UDP packet to port 3391.

Proof-of-concept exploit for Apache mod_http2 double-free vulnerability (CVE-2026-23918) with recon, exploit, and RCE risk assessment phases.

GitLab CE/EE Preauth RCE using ExifTool