
cve-2025-55182
Technical penetration testing writeup demonstrating exploitation of CVE-2025-55182 in Next.js, credential harvesting from SQLite, and privilege…

Technical penetration testing writeup demonstrating exploitation of CVE-2025-55182 in Next.js, credential harvesting from SQLite, and privilege…

OpenSTAManager v2.9.8 and earlier versions contain a critical OS Command Injection vulnerability in the P7M (signed XML) file decoding function.

DCOM in memory and fileless lateral movement techniques through .Net deserilization

Apache ActiveMQ RCE via Jolokia vulnerability analysis and reproduction notes

CVE-2024-24590 – ClearML RCE via unsafe pickle artifact deserialization (0.17.0–1.14.2)

Automated exploitation framework for CVE-2025-55182 (Next.js RCE) with subdomain enumeration, vulnerability scanning, payload generation, and…

CVE-2025-48593

Proof-of-concept exploit for CVE-2025-32433, enabling unauthenticated remote code execution in Erlang/OTP SSH. Includes Docker setup and reverse…

Metasploit RCE on HFS 2.3 - CVE-2014-62

Proof-of-concept exploit for a critical stack-based buffer overflow in Fortinet products, enabling unauthenticated remote code execution via the…

Fortinet Fortimanager Unauthenticated Remote Code Execution AKA FortiJump CVE-2024-47575

Pre-Auth Exploit for CVE-2024-40711

Exploit code and technical analysis for CVE-2024-38063, a critical Windows TCP/IP RCE vulnerability, including CVSS metrics and exploitation details…

Exploit for CVE-2022-22963 remote command execution in Spring Cloud Function

Proof-of-concept exploit for CVE-2022-24644, demonstrating unauthenticated remote code execution via DNS spoofing against KeyMouse Windows 3.08…

Java-based proof-of-concept exploit for CVE-2021-44228 (Log4Shell) enabling remote command execution, OS information gathering, and arbitrary…

Exploit for CVE-2021-3129

CVE-2020-7200: HPE Systems Insight Manager (SIM) RCE PoC