
sjet
Exploit insecure JMX services with remote payload deployment, command execution, shell access, and JavaScript scripting for penetration testing of…

Exploit insecure JMX services with remote payload deployment, command execution, shell access, and JavaScript scripting for penetration testing of…

Bash proof-of-concept exploit for CVE-2020-9484 enabling remote code execution on Apache Tomcat via insecure deserialization in file uploads, with…

Proof-of-concept exploit for React2Shell (CVE-2025-55182) enabling pre-authentication remote code execution on vulnerable Next.js/React Server…

Proof-of-concept exploit for CVE-2025-66478, a critical RCE in Next.js via insecure deserialization in React Server Components. Includes payload…

Proof-of-concept exploit for CVE-2025-55182 (React2Shell) enabling pre-authentication remote code execution via insecure deserialization in React's…

Remote code execution exploit for Apache ActiveMQ CVE-2023-46604, leveraging insecure deserialization in OpenWire protocol to execute arbitrary shell…

Python PoC exploit for CVE-2023-47464 targeting GL-AX1800 router vulnerabilities including CSRF, insecure file upload, path traversal, and RCE.…

Authenticated remote code execution exploit for eXtplorer 2.1.15 on Joomla. Python-based tool targeting insecure permissions to gain shell access.

Master's thesis research on CVE-2025-55182 (React2Shell). Modular exploitation framework with 6 attack scenarios (RCE, exfiltration, defacement),…

Python exploit for CVE-2023-46604 targeting insecure deserialization in Apache ActiveMQ OpenWire protocol to achieve remote code execution via…

Python proof-of-concept exploit for CVE-2025-55182, a pre-authentication remote code execution vulnerability in React Server Components via insecure…

IBM i Access Client Solutions < 1.1.9.4 - Remote code execution via insecure deserialisation

Proof-of-concept exploit for CVE-2023-28354, demonstrating unauthenticated remote command execution on Opsview Windows Agent via insecure NRPE…

Proof-of-concept exploit for CVE-2019-12409, demonstrating unauthenticated remote code execution in Apache Solr 8.1.1/8.2.0 via insecure default JMX…

A simple C2 Framework written in modern C++

A PoC Exploit for CVE-2024-0757 - Insert or Embed Articulate Content into WordPress Remote Code Execution (RCE)

Java deserialization exploit targeting Elasticsearch 1.5.2 transport protocol (port 9300) using Groovy MethodClosure chain for remote code execution…