
ShellUpload
PHP-based web shell uploader for penetration testing, enabling file upload and remote command execution on vulnerable web servers.

PHP-based web shell uploader for penetration testing, enabling file upload and remote command execution on vulnerable web servers.

PoC exploits CVE-2025-24893 , a remote code execution (RCE) vulnerability in XWiki caused by improper sandboxing in Groovy macros rendered…

Implementation of CVE-2022-0847 as a shellcode

This is my own exploit for CVE-2023-46818 happy hacking!

This exploit was written to study some concepts, enjoy!

PoC to exploit lenovo dispatcher driver (LnvMSRIO.sys) (CVE-2025-8061)

Modified standalone exploit ported for Python 3

Proof-of-concept local privilege escalation tool exploiting a kernel XFRM/ESP vulnerability (CVE-2026-43503) via crafted AES-CBC encrypted payloads…

Full-chain exploit for CVE-2025-2783 (Ipcz Sandbox Escape & RCE).

CVE-2014-6287

A proof of concept of an SEH overflow with arbitrary dll injection

Exploit POC for the bug CVE-2019-8781, found by @LinusHenze

Python exploit for CVE-2022-22963 (Spring4Shell) targeting Spring Cloud Function RCE. Automates reverse shell delivery via wget and bash one-liner…

CVE-2024-36401 exploit with webshell-like functionality for limited environments, supporting self-signed TLS sessions and remote command execution…

exp of CVE-2022-0847

Proof-of-concept exploit for CVE-2019-0708 (BlueKeep) targeting Windows RDP, with shellcode for x86 systems. Intended for authorized security testing…

Proof-of-concept exploit for CVE-2024-10793 targeting WordPress wp-security-audit-log plugin. Demonstrates account takeover, privileged user…

weaponized radare2 vulnerability found by @CaptnBanana and blenk92