
CVE-2025-32432-exploit-by-P34NUT
Reliable CVE-2025-32432 pre-auth RCE exploit for Craft CMS 3.x/4.x/5.x, works where other public PoCs fail

Reliable CVE-2025-32432 pre-auth RCE exploit for Craft CMS 3.x/4.x/5.x, works where other public PoCs fail

Python CLI that exploits CVE-2026-48907 in Joomla JCE via profile-import upload, verifies shell paths, and opens an interactive command channel on…

Python PoC exploiting CVE-2024-2044 in pgAdmin 4 (<=8.3) via authenticated path traversal and unsafe pickle deserialization to achieve remote code…

A cross platform C2/post-exploitation framework.

CVE-2026-33017 - Langflow Unauthenticated RCE Exploit

Multi-CVE exploit tool for pre-auth remote code execution on Ivanti Sentry and FortiSandbox. Features interactive shell, webshell deployment,…

CVE-2024-49375、CVE-2021-42556、CVE-2021-41127

Exploit for CVE-2026-41940 providing direct shell access via websocket and persistence through root API key injection.

Unauthenticated RCE in dedoc/scramble — PoC, Nmap NSE & Nuclei template.

PS5 homebrew enabler payload offering post-exploitation features: custom plugin/payload loading, unsigned fself/fpkg support, debug settings, FTP…

PoC Authentication Bypass to RCE to Exploit CVE-2025-31161

poc for CVE-2025-24252 & CVE-2025-24132

Go-based proof-of-concept for CVE-2025-55182, a critical RCE in React Server Components. Features vulnerability checking, command execution, memory…

A standalone Rust implementation of the CVE-2007-2447 exploit targeting Samba smbd 3.0.20-Debian.

Remote Code Execution Exploit for Langflow (CVE-2025-3248) - [ By S4Tech ]

Proof-of-concept backdoor for SCCM Management Point using rogue COM service for persistent remote command execution as SYSTEM.

Automated exploit for CVE-2024-415770: leverages SSRF to achieve RCE, registers an agent on the teamserver, opens a socket, and injects an SSH key…

CVE-2024-53691