
CVE-2026-80099
Newfold plugins (wp-module-data <= 2.9.7) Unauthenticated

Newfold plugins (wp-module-data <= 2.9.7) Unauthenticated

Authenticated RCE exploit for WBCE CMS <= 1.6.3 that creates a malicious module zip with a PHP reverse shell and netcat listener.

Exploit module for FreePBX delivering a reverse shell payload to achieve remote command execution and persistent shell access, designed for…

Python exploit for Samba 3.0.20-3.0.25rc3 'username map script' command injection, providing unauthenticated remote code execution and reverse shell.

PowerShell to Slack C2

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.

Metasploit module for MailEnable CVE-2022-36934 authentication bypass RCE

This is a proof-of-concept Metasploit module exploit for CVE-2015-1578, a buffer overflow vulnerability in Achat 0.150 beta7 on Windows. Exploitation…

Rejetto HTTP File Server (HFS) 2.x - Unauthenticated RCE exploit module (CVE-2024-23692)

CVE-2018-10933

Python RCE PoC with reverse-shell listener for CVE-2026-42945 (NGINX Rift)

CVE-2022-31491

this is a metasploit exploit module for CVE-2024-25096 and CVE-2023-3452

A modified version of the Rapid7 Metasploit module for CVE-2021-27877 that supports direct command execution for reliable vulnerability validation.…

Crestron/Barco/Extron/InFocus/TeqAV Remote Command Injection (CVE-2019-3929) Metasploit Module

Metasploit module for Apache Struts CVE-2017-9791 Remote Code Execution Vulnerability

Crestron AirMedia AM-100 RCE (CVE-2016-5640) Metasploit Module

A Python replicated exploit for Webmin 1.580 /file/show.cgi Remote Code Execution