
CVE-2025-32432
Python exploit for CVE-2025-32432, an unauthenticated RCE in Craft CMS via Yii2 __class injection, with command execution and reverse shell support.

Python exploit for CVE-2025-32432, an unauthenticated RCE in Craft CMS via Yii2 __class injection, with command execution and reverse shell support.

Python PoC exploiting CVE-2025-27636, an Apache Camel header injection RCE, supporting command execution, file reads, and reverse shell payloads.

Proof of Concept (PoC) for CVE-2022-42889 (Text4Shell) targeting Apache Commons Text versions prior to 1.10.0. This script automates Remote Code…

CVE-2023-46604-RCE exploit with Linux reverse shell payload

CVE-2025-49844

Automated exploit for CVE-2025-49132, a critical unauthenticated RCE in Pterodactyl Panel. Leverages LFI via locale endpoint to deploy persistent web…

IBM i DDM Unauthenticated RCE - Java Reverse Shell

Detects and exploits CVE-2024-21762 pre-authentication RCE in FortiGate SSL VPN, featuring baseline validation, automatic exploitation, ROP…

Proof of Concept for Authenticated RCE in Crafty Controller <= 4.6.1

Remote root exploit for SAMBA CVE-2017-7494 that compiles a shared library payload, uploads it to a writable share, and triggers loading to spawn a…

XWiki Unauthenticated RCE Exploit for Reverse Shell

Proof-of-concept exploit for CVE-2021-41773, a path traversal and remote code execution vulnerability in Apache HTTP Server 2.4.49. Automates…

Reverse shell for CVE-2024-28397.

CVE-2025-24893 RCE exploit for XWiki with reverse shell capability

This script exploits CVE-2025-49619 in Skyvern to execute a reverse shell command.

Scanner and exploit for CVE-2025-3248, an unauthenticated RCE in Langflow AI. Includes a vulnerability checker and a reverse shell payload generator…

nim-reverse-shell

Node.js reverse shell payload generator for penetration testing. Creates bind and reverse shells in JavaScript.