
CVE-2025-68937
Automated PoC exploit for CVE-2025-68937 — Gitea/Forgejo Template Symlink RCE. Any authenticated user can get a shell as the git service user.

Automated PoC exploit for CVE-2025-68937 — Gitea/Forgejo Template Symlink RCE. Any authenticated user can get a shell as the git service user.

CVE-2026-66374: Knot Resolver 6.3.0 DNS-over-QUIC heap overflow (RCE)

A number of exploits and tools I've written for CVEs accredited to Marshall Whittaker/oxagast

complex webshell manager, quasi-http botnet.

Grant remote access to user account without sharing credentials

Gogs service Exploit and get the root user

Authenticated (privileged) remote command execution in LimeSurvey Version 5.2.4 via upload and install plugins allows a remote user to upload…

vsftpd 2.3.4 Backdoor Exploit

Takes advantage of CVE-2018-10933

Glass Cage is a zero-click PNG-based RCE chain in iOS 18.2.1, bypassing LockDown mode protection by exploiting ImageIO (CVE-2025-43300), then…

(CVE-2019-6340, CVE-2018-7600) drupal8-REST-RCE


PoC Authentication Bypass to RCE to Exploit CVE-2025-31161

PoC | XWiki Platform 15.10.10 - Remote Code Execution

CVE-2023-34468: Remote Code Execution via DB Components in Apache NiFi