
CVE-2025-24813-POC
Proof-of-concept exploit for CVE-2025-24813, demonstrating Apache Tomcat RCE via misconfigured file-based session persistence in DefaultServlet.

Proof-of-concept exploit for CVE-2025-24813, demonstrating Apache Tomcat RCE via misconfigured file-based session persistence in DefaultServlet.

Python PoC for CVE-2026-87902, an unauthenticated WordPress path traversal RCE via get_page_template(), with version fingerprinting, theme checks,…

F5 BIG-IP iControl REST vulnerability RCE exploit with Java including a testing LAB

Python PoC exploiting CVE-2026-87902, an unauthenticated path traversal in WordPress locate_template() leading to LFI and PEAR-based RCE, with safe…

Python PoC for CVE-2026-90817, an unauthenticated REDCap RCE via survey passthrough routing and file-path injection, with a Docker lab and…

Python exploit scanner for Apache 2.4.50 (CVE-2021-42013) detecting path traversal and remote code execution with bulk scanning and Docker lab…

PoC and Docker lab for CVE-2026-49869, an unauthenticated RCE in Kestra OSS via an AuthenticationFilter path bypass that allows flow creation and…

Python-based exploit for CVE-2025-55182 (React Server Components RCE) with interactive shell, reverse shell, batch scanning, and Docker-based…

Lab environment and PoC exploit for CVE-2025-55182 (React2Shell), a critical RCE vulnerability in React Server Components. Includes vulnerable app,…

A collection of scripts which may come in handy during your freedom fighting activities.

On-demand reverse shell service that auto-detects target environment and executes appropriate payload for remote access during penetration tests.

Docker-based lab environment and exploit for CVE-2019-7609 (Kibana Timelion RCE) with reverse shell payload and patch analysis.

Python exploit for Apache Struts2 S2-062 (CVE-2021-31805) remote code execution, with Docker-based reproduction environment and reverse shell payload…

Step-by-step walkthrough of CVE-2017-18349 Fastjson deserialization RCE exploitation, covering attack surface identification, fingerprinting, JNDI…

CVE-2020-15227 exploit

Step-by-step exploit writeup for CVE-2017-11610 (Supervisord XML-RPC RCE) with attack surface analysis, namespace traversal discovery, and…

a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC). It also includes a realistic "Lab Environment" to safely test…

Proof-of-concept exploit for CVE-2026-24061, a Telnet NEW-ENVIRON RCE vulnerability, with Docker reproduction environment and Python detection script.