
CVE-2023-31902
Pre-auth RCE exploit for Mobile Mouse 3.6.0.4 via TCP (port 9099) and WebSocket (port 35913) with Python scripts for unauthenticated command…

Pre-auth RCE exploit for Mobile Mouse 3.6.0.4 via TCP (port 9099) and WebSocket (port 35913) with Python scripts for unauthenticated command…

Easy peasy file uploads

This utility was created during research involving MCPJam v1.4.2. The application exposes an API endpoint that accepts a server configuration object.…

Python 2.7

Exploit for CVE-2015-8522 targeting Tivoli FastBack Server with stack-based buffer overflow, ASLR/DEP bypass, and automated reverse-shell…

Agentic C2-style MCP server for Frida instrumentation on rooted Android and jailbroken iOS.

Exploits CVE-2026-31816 in Budibase to bypass authentication, upload a malicious datasource plugin, and execute a reverse shell for remote access.

Exploit implementation for CVE-2014-6287, targeting a remote code execution vulnerability in a web application. Provides a proof-of-concept for…

Intentionally vulnerable Next.js app for CVE-2025-55182 security research and CTF challenges

Single-file PHP shell

A webshell framework for penetration testers.

POC for CVE-2021-35448 based on https://www.exploit-db.com/exploits/49601

Authenticated Remote Command Execution - Webmin <= 1.910

CVE-2021-38163 - SAP NetWeaver AS Java Desynchronization Vulnerability

Proof-of-concept exploit for CVE-2025-30065 demonstrating remote class instantiation and SSRF via malicious Parquet files in Java applications.

Proof-of-concept exploit for authenticated remote code execution via command injection in ProApps Enterprise Appliance ping functionality, with…

Server-Side Template Injection Exploit

Primefaces <= 5.2.21, 5.3.8 or 6.0 - Remote Code Execution Exploit