
CVE-2025-55182
Master's thesis research on CVE-2025-55182 (React2Shell). Modular exploitation framework with 6 attack scenarios (RCE, exfiltration, defacement),…

Master's thesis research on CVE-2025-55182 (React2Shell). Modular exploitation framework with 6 attack scenarios (RCE, exfiltration, defacement),…

Detailed analysis and exploit for a remote code execution vulnerability (CVE-2024-38366) in the CocoaPods Trunk Server, enabling OS command injection…

This exploit was created to exploit an XXE (XML External Entity). Through it, I read the backend code of the web service and found an endpoint where…

Proof-of-concept exploit for CVE-2023-36845 enabling unauthenticated remote code execution on Juniper SRX firewalls and EX switches via PHP…

PoC exploit and NSE scanner for CVE-2021-21985, a vCenter Server RCE vulnerability in the vSAN Health Check plugin, with manual exploitation steps…

Proof-of-concept exploit for unauthenticated remote code execution in Rejetto HTTP File Server (HFS) 2.3m (CVE-2024-23692). Includes target discovery…

Python-based proof-of-concept exploit for CVE-2022-32548, an unauthenticated remote code execution vulnerability in DrayTek routers via buffer…

Proof-of-concept exploit for CVE-2025-31324, a remote code execution vulnerability in SAP NetWeaver, with Shodan dorks for target discovery and…

Proof-of-concept exploit for Apache mod_http2 double-free vulnerability (CVE-2026-23918) with recon, exploit, and RCE risk assessment phases.

Unauthenticated remote code execution exploit for Langflow applications vulnerable to CVE-2025-3248, targeting the /api/v1/validate/code endpoint…

Node.js exploit for CVE-2015-3224, achieving unauthenticated RCE on Rails web-console by spoofing X-Forwarded-For to bypass IP whitelist and…

Exploit for CVE-2021-40539: RCE in Zoho ManageEngine ADSelfService Plus. Includes detection script, Fofa search syntax, and webshell deployment for…

Exploit for CVE-2021-40539 targeting Zoho ManageEngine ADSelfService Plus RCE with authentication bypass. Includes batch scanning and webshell…

GitLab CE/EE pre-auth RCE exploit via ExifTool with version detection, reverse shell, SSH key injection, and password modification.

Open-source exploitation framework with modular payload, encoder, and auxiliary system for penetration testing, vulnerability validation, and…

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

Free implementation of Remote Desktop Protocol (RDP) providing client and library for secure remote desktop access with authentication, encryption,…

Secure tunneling daemon implementing VPN protocols with TLS encryption, certificate authentication, and routing/firewall configuration for private…