
CVE-2021-30461
Proof-of-concept exploit for CVE-2021-30461, a remote code execution vulnerability in VoIPMonitor web interface. Demonstrates unauthenticated RCE via…

Proof-of-concept exploit for CVE-2021-30461, a remote code execution vulnerability in VoIPMonitor web interface. Demonstrates unauthenticated RCE via…

Proof of concept for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely.

Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution

Powershell reverse shell using HTTP/S protocol with AMSI bypass and Proxy Aware

RCE on Apache Solr using deserialization of untrusted data via jmx.serviceUrl

Remote Administration Toolkit (or Trojan) for POSiX (Linux/Unix) system working as a Web Service

pinky - The PHP mini RAT (Remote Administration Tool)

🍵 Gitea repository migration remote command execution exploit.


CVE-2022-21907 Vulnerability PoC

Exploit for CVE-2017-6079 blind command injection in Edgewater Edgemarc devices; reads remote files and uploads/executes ELF payloads via hidden…

Metasploit-Framework modules (scanner and exploit) for the CVE-2021-41773 and CVE-2021-42013 (Path Traversal in Apache 2.4.49/2.4.50)

Python 2.7

Python exploit script for CVE-2024-23692, a template injection RCE in Rejetto HFS 2.3m. Supports single and batch URL exploitation with custom…

Apache ActiveMQ Remote Code Execution Exploit

Another spring4shell (Spring core RCE) POC

CVE-2026-33017 - Langflow Unauthenticated RCE Exploit

Python RCE PoC with reverse-shell listener for CVE-2026-42945 (NGINX Rift)