
CVE-2025-68937
Automated PoC exploit for CVE-2025-68937 — Gitea/Forgejo Template Symlink RCE. Any authenticated user can get a shell as the git service user.

Automated PoC exploit for CVE-2025-68937 — Gitea/Forgejo Template Symlink RCE. Any authenticated user can get a shell as the git service user.

Gogs service Exploit and get the root user

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

A number of exploits and tools I've written for CVEs accredited to Marshall Whittaker/oxagast

Full walkthrough of HTB's Reactor machine — exploit CVE-2025-55182 to gain a shell, then get root via an exposed Node.js debugger. Step-by-step with…

Exploit script for CVE-2025-50946

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

CVE-2025-32433-available-for-windows-victims

PoC exploit for CVE-2021-33026 that poisons Redis cache in Flask-Cache to achieve remote code execution via malicious pickle deserialization.

A collection of selenium tests that might aid it takeover of a selenium node

Simple exploit for Wing FTP Server RCE (CVE-2025-47812) to run commands and get a reverse shell. For educational use only.

Python exploit for CVE-2020-14008 in ManageEngine Applications Manager delivering a SYSTEM-level reverse shell via authenticated remote code…

A PoC for CVE-2025-24813

An exploit for Four-Faith routers to get a reverse shell

Go-based WinRM client for remote command execution and lateral movement on Windows systems during penetration tests.

Get Keyboard,Mouse,ScreenShot,Microphone Inputs from Target Computer and Send to your Mail.

Pentestmonkeys' PHP reverse shell with dynamic host and port passing through GET request parameters

CVE-2019-18818/19606 Strapi RCE