
CVE-2026-87902
Proof-of-concept exploit for CVE-2026-87902, a WordPress Core pre-auth path traversal chaining LFI to remote code execution.

Proof-of-concept exploit for CVE-2026-87902, a WordPress Core pre-auth path traversal chaining LFI to remote code execution.

Exploiting a Reflected Cross-Site Scripting (XSS) attack to get a Remote Command Execution (RCE) through the Webmin's running process feature

An exploit for Four-Faith routers to get a reverse shell

Go-based WinRM client for remote command execution and lateral movement on Windows systems during penetration tests.

50 first stargazers will get get the tool via email

Python exploit for CVE-2018-10933 that bypasses libssh server authentication and spawns an unauthenticated shell on vulnerable SSH servers.

A Windows Remote Administration Tool in Visual Basic with UNC paths

test for CVE-2018-6574: go get RCE pentesterlab

This script allows for remote code execution (RCE) on Oracle WebLogic Server

Exploit script for CVE-2025-50946

Remote shell on CVE-2009-4623

An exploit to get root in vsftpd 2.3.4 (CVE-2011-2523) written in python

CVE-2007-2447 exploit written in python to get reverse shell

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

Exploits CVE-2021-40444 in Microsoft Office Word to achieve remote code execution through the MSHTML engine by injecting malicious content into a…


double-free bug in WhatsApp exploit poc

Double-Free BUG in WhatsApp exploit poc.