
Craft-CMS-Exploit
Python exploit for Craft CMS CVE-2023-41892 Remote Code Execution vulnerability, delivering a PHP reverse shell for authorized penetration testing.

Python exploit for Craft CMS CVE-2023-41892 Remote Code Execution vulnerability, delivering a PHP reverse shell for authorized penetration testing.

D-Link NAS Command Execution Exploit

Multi-threaded Telnet vulnerability scanner that exploits CVE-2026-24061 via environment variable injection, verifies root access, and provides an…

CVE-2019–15107 - Unauthenticated RCE Webmin <=1.920

CVE-2026-6279

Python exploit for CVE-2023-45878, an unauthenticated arbitrary file upload in Gibbon CMS, enabling RCE via webshell upload and interactive shell…

OpenSTAManager RCE Exploit (CVE-2026-38751)

VsFTPd 2.3.4 Backdoor Command Execution

Exploit for EasyNAS version 1.1.0. The vulnerability exploited is a command injection flaw, which requires authentication.

Refurbish

Exploits Oracle WebLogic Server RCE (CVE-2020-14882) to execute commands on vulnerable targets, capturing output via HTTP listener.

CVE-2020-14882 rewritten in PowerShell

Python exploit for VSFTP 2.3.4 backdoor (CVE-2011-2523) that triggers the backdoor and provides shell access on port 6200.

CVE-2023-31756 Proof of Concept - Remote Code Execution for Archer V1/V2 Routers

This Python exploit script targets a vulnerable Laravel Filemanager created by UniSharp, which allows authenticated users to bypass file restrictions…

This is a script written in Python that allows the exploitation of the Metabase's software security flaw described in CVE-2023-38646.

A script to test an RDP host for sticky keys and utilman backdoor.

This is an easy to use PoC script to exploit React2Shell-CVE-2025-55182 Nextjs vulnerability. This will help to gain a reverse shell.