
CVE-2023-41425
WonderCMS v3.2.0 - v3.4.2 XSS to RCE exploit

WonderCMS v3.2.0 - v3.4.2 XSS to RCE exploit

Reverse shell for CVE-2024-28397.

Python exploit for CVE-2007-2447 that triggers Samba username map script command injection to open a reverse shell on vulnerable targets.

Open Web Analytics 1.7.3 - Remote Code Execution Exploit v2

Proof-of-concept exploit for CVE-2024-23738 targeting Postman on macOS. Automates vulnerability detection and code injection via Electron settings to…

Proof-of-concept exploit for CVE-2024-23742 in Loom for macOS. Validates vulnerability and injects arbitrary code via RunAsNode settings to gain a…

Carga de archivos sin restricciones en la funcionalidad de carga de archivos grandes en `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` en…

this script is exploit for wordpress old plugin gwolle

Proof-of-concept exploit for CVE-2023-38831 targeting vulnerable versions, delivering a reverse shell via automated exploitation.

Automated exploit tool for CVE-2024-23743 targeting Notion macOS via RunAsNode and enableNodeClilnspectArguments, enabling remote code execution and…

Vulnerabilidad de carga de archivos sin restricciones en **Chamilo LMS** (<= v1.11.24).

This script exploits CVE-2025-62369 in Xibo CMS to execute a reverse shell command.

Python exploit for CVE-2025-6002 targeting authenticated arbitrary file upload in VirtueMart < 4.4.10. Logs in, uploads a PHP webshell, and triggers…

Exploit for CVE-2024-39205, a js2py sandbox escape that enables remote code execution and establishes a reverse shell.

Magento APSB25-94 Unauthenticated File Upload to RCE (CVE-2026-XXXX) - Eval Shell + Probe Scanner

POC exploit for Dolibarr <= 17.0.0 (CVE-2023-30253)

MS08-067 | CVE-2008-4250

CVE-2018-7600 | Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' RCE