
CVE-2024-23897
Jenkins RCE Arbitrary File Read CVE-2024-23897

Jenkins RCE Arbitrary File Read CVE-2024-23897

CVE-2019-12409: RCE Vulnerability Due to Bad Defalut Config in Apache Solr

A PoC Java Stager which can download, compile, and execute a Java file in memory.

Exploit for CVE-2021-22005, a pre-auth arbitrary file upload vulnerability in VMware vCenter Server, enabling remote code execution via webshell…

PowerShell-based reverse shell with background task execution, file transfer, and dual persistence mechanisms via registry and startup folder for red…

This repo contains a proof-of-concept exploit for CVE-2026-15409. It establishes non-root remote code execution on SonicWall SMA 1000 by implementing…

Windows Network File System Remote exploit for CVE-2022-30136

Python exploit for CVE-2020-17518, allowing arbitrary file write via Apache Flink REST API. Supports single target and batch scanning from a file.

Proof-of-concept exploit for Log4j 2.17.0 RCE (CVE-2021-44832) using JNDI injection with malicious configuration file deployment.

Proof-of-concept exploit for CVE-2023-33253, enabling authenticated remote code execution in LabCollector 6.0-6.15 via malicious PHP file upload.

CVE-2024-22515 arbitrary file upload and CVE-2024-22514 remote code execution for AgentDVR 5.1.6.0 (Authenticated)

Proof-of-concept exploit for CVE-2026-20253, enabling unauthenticated remote code execution on vulnerable Splunk Enterprise instances via file write…

Python exploit for CVE-2020-10189 targeting ManageEngine Desktop Central, enabling unauthenticated remote code execution via file upload…

Automated exploitation framework for CVE-2025-55182 (Next.js RCE) with subdomain enumeration, vulnerability scanning, payload generation, and…

Python exploit for CVE-2023-4220, an unauthenticated remote code execution in Chamilo LMS via unrestricted file upload, enabling web shell deployment…

Exploit for CVE-2024-23897 in Jenkins, enabling file read and remote code execution via crafted requests. Includes Docker setup and Groovy scripts…

Proof-of-concept exploit for CVE-2014-3120 Elasticsearch remote code execution, enabling file read and append on the host system via browser-based…

Proof-of-concept exploit for CVE-2024-39943, demonstrating remote code execution via file upload in a Node.js HFS server using…