
datapower-redis-rce-exploit
A POC for IBM Datapower Authenticated Redis RCE Exploit abusing the Test Message Function (CVE-2020-5014)

A POC for IBM Datapower Authenticated Redis RCE Exploit abusing the Test Message Function (CVE-2020-5014)

Proof-of-concept exploit for CVE-2026-54806: unauthenticated PHP object injection in WP Activity Log plugin enabling blind RCE via User-Agent header.…

Proof-of-concept and lab pack for CVE-2026-77991, a privileged PHP file-write RCE in Joomla Event Manager through 5.0.0, with Docker lab and witness…

Proof-of-concept exploit for CVE-2025-49131, a sandbox escape in FastGPT allowing arbitrary file read/write, import bypass, and remote code execution…

Client for Cloudflare Tunnel enabling secure outbound-only connections to origins via Zero Trust architecture. Supports HTTP, WebSocket, SSH, and RDP…

Dockerized Python exploit for CVE-2019-11043, a critical PHP-FPM remote code execution vulnerability in NGINX configurations. Includes setup, usage,…

Proof-of-concept exploit for CVE-2026-65400 enabling authenticated file read/write, reverse shells, and persistence on macOS via Apple ScreenSharing.

Docker-based lab environment and exploit for CVE-2019-7609 (Kibana Timelion RCE) with reverse shell payload and patch analysis.

Proof-of-concept exploit for CVE-2022-24706 targeting Apache CouchDB 3.2.1 and below. Demonstrates remote command execution via Erlang Distribution…


Bash-based PoC exploit for CVE-2025-9074 targeting unauthenticated Docker Engine API to achieve container escape and remote code execution via…

Exploit for the PHP 8.1.0-dev backdoor vulnerability (CVE-2021-21707)

The ultimate WinRM shell for hacking/pentesting

Step-by-step walkthrough of CVE-2017-18349 Fastjson deserialization RCE exploitation, covering attack surface identification, fingerprinting, JNDI…

MS17-010_CVE-2017-0143

Proof-of-concept exploit for CVE-2026-75430, achieving unauthenticated remote code execution on PowerJob Worker via arbitrary JAR loading through the…

this is a metasploit exploit module for CVE-2024-25096 and CVE-2023-3452

Exploit for CVE-2021-22911: pre-auth blind NoSQL injection in Rocket Chat 3.12.1 enabling account takeover and remote code execution via webhook…