
CVE-2021-42013
Exploit for Apache 2.4.49/2.4.50 path traversal and RCE (CVE-2021-42013). Includes Docker setup and script to test path traversal, execute commands,…

Exploit for Apache 2.4.49/2.4.50 path traversal and RCE (CVE-2021-42013). Includes Docker setup and script to test path traversal, execute commands,…

Exploit script for Apache HTTP Server 2.4.49/2.4.50 path traversal and remote code execution (CVE-2021-41773). Includes Docker-based reproduction…

Exploit script for CVE-2025-49844, a use-after-free vulnerability in Redis Lua scripting enabling remote code execution. Targets specific Redis…

Reproduces CVE-2020-15778 SCP command injection exploit with Docker-based client-server setup for testing remote code execution and reverse shell…

Proof-of-concept exploit for CVE-2024-25082, demonstrating remote code execution in FontForge via crafted ZIP archives. Includes payload generator,…

Proof-of-concept exploit for CVE-2025-32433, enabling unauthenticated remote code execution in Erlang/OTP SSH. Includes Docker setup and reverse…

Authenticated remote code execution exploit for Webmin (CVE-2019-15642). Provides a Python script to execute arbitrary commands on vulnerable Webmin…

Security gateway for AI agents - credential-isolated API proxying and policy-gated remote execution (conclaves). Reduce the blast radius!

Docker API CVE-2025-9074 PoC (Proof-Of-Concept). A sophisticated exploitation framework for CVE-2025-9074, targeting unauthenticated Docker API…

Step-by-step exploit writeup for CVE-2017-11610 (Supervisord XML-RPC RCE) with attack surface analysis, namespace traversal discovery, and…

Proof-of-concept exploit for CVE-2025-32433, an Erlang/OTP SSH pre-authentication channel confusion vulnerability, demonstrating authentication…

Automated Mass Exploiter

SambaCry exploit and vulnerable container (CVE-2017-7494)

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

Python-based exploit for CVE-2025-55182 (React Server Components RCE) with interactive shell, reverse shell, batch scanning, and Docker-based…

Exploit for CVE-2022-22963 (Spring Cloud Function SpEL injection) enabling remote code execution and reverse shell. Includes Docker-based lab for…

PHP shells that work on Linux OS, macOS, and Windows OS.

A community-curated, verified collection of Proof-of-Concept exploits for CVEs disclosed in 2026.