
XploitSPY
Cloud-based Android monitoring tool with GPS tracking, microphone recording, SMS/call logging, live notification capture, file explorer, and built-in…

Cloud-based Android monitoring tool with GPS tracking, microphone recording, SMS/call logging, live notification capture, file explorer, and built-in…

Wordpress Plugin Canto < 3.0.5 - Remote File Inclusion (RFI) and Remote Code Execution (RCE)

Native Nim WinRM shell with NTLM, Kerberos, file transfer, in-memory helpers, and AD/OPSEC reporting

Python exploit for CVE-2023-45878, an unauthenticated arbitrary file upload in Gibbon CMS, enabling RCE via webshell upload and interactive shell…

POC for CVE-2023-4220 - Chamilo LMS Unauthenticated Big Upload File Remote Code Execution

Bash proof-of-concept exploit for CVE-2020-9484 enabling remote code execution on Apache Tomcat via insecure deserialization in file uploads, with…

CVE-2024-50623 POC - Cleo Unrestricted file upload and download

Critical 0 Day in Car Rental Management System Versions 1.0 - 1.3

Encrypted command-and-control tunnel over DNS protocol. Creates stealthy C&C channels for penetration testing, with file transfer, shell access, and…

POC - Unauthenticated RCE Flaw in Rejetto HTTP File Server - CVE-2024-23692

CVE-2026-57827 — RSFiles! Joomla Component Unauthenticated File Upload RCE. Split-controller upload bypass. CVSS 9.8 | CWE-434 | com_rsfiles < 1.17.12

Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload (CVE-2026-3891) PoC

Exploit for CVE-2021-21972, a remote code execution vulnerability in VMware vCenter Server via arbitrary file upload on port 443.

Exploit for CrushFTP SSTI vulnerability (CVE-2024-4040) enabling unauthenticated file read, authentication bypass, and remote code execution on…

This is an Exploit for Unrestricted file upload in big file upload functionality in Chamilo-LMS for this location…

DJ-Classifieds Joomla Component Unauthenticated File Upload RCE. 3-string filter bypass via PHP short tags. CVSS 10.0 | CWE-434 | com_djclassifieds <…

Cisco Email Security Appliance: Remote Code Execution - RCE from config file

CVE-2021-42669 - Remote code execution via unrestricted file upload vulnerability in the Engineers online portal system.