
WAMpage
WAMpage - A WebOS root LPE exploit chain (CVE-2022-23731)

WAMpage - A WebOS root LPE exploit chain (CVE-2022-23731)

Python exploit for CVE-2022-22963 (Spring4Shell) targeting Spring Cloud Function RCE. Automates reverse shell delivery via wget and bash one-liner…

POC for exploit of CVE-2011-1237

PoC of CVE-2021-4034 (PwnKit) for personal training purposes.

This is a proof-of-concept exploit for CVE-2015-1578, a buffer overflow vulnerability in Achat 0.150 beta7 on Windows. Exploitation leads to remote…

coldfusion exploit based on https://cvedetails.com/cve/CVE-2009-2265/

Exploit script for CVE-2020-24186 in WordPress that uploads a camouflaged PHP webshell and provides interactive or reverse shell access with optional…

Remote Code Execution via Use-After-Free in JScript.dll (CVE-2025-30397)

Python exploit for vsFTPd 2.3.4 backdoor (CVE-2011-2523) that triggers a hidden shell on port 6200 via a crafted username, enabling remote command…

A personal collection of Windows CVE I have turned in to exploit source, as well as a collection of payloads I've written to be used in conjunction…

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

CVE-2024-36401 exploit with webshell-like functionality for limited environments, supporting self-signed TLS sessions and remote command execution…

Proof-of-concept exploit for CVE-2023-38831 targeting vulnerable versions, delivering a reverse shell via automated exploitation.

Proof of concept for CVE-2021-27965 (Stack-based Buffer Overflow)

Vbullettin RCE - CVE-2025-48827

Automated deployment tool for CVE-2024-31317 PoC on Android 9-13, enabling privilege escalation via Zygote injection and reverse shell execution.

CVE affecting ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier.

Implementation of CVE-2022-0847 as a shellcode