
exploitgym
ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.

ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.


This is POC of CVE-2024-29671


C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection

A simple tool to interact with web shells and command injection vulnerabilities

Atlassian Jira unauthen template injection

PoC exploits CVE-2025-24893 , a remote code execution (RCE) vulnerability in XWiki caused by improper sandboxing in Groovy macros rendered…

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

Unauthenticated 0-click RCE exploit for CVE-2024-50498. Exploits a code injection vulnerability in the LUBUS WP Query Console plugin to execute…

Evince/xreader/Atril RCE exploit to CVE-2026-46529


A bash scanner for detecting CVE-2025-55182 vulnerability in Next.js applications. And a PoC nodejs script

POC exploit for Dolibarr <= 17.0.0 (CVE-2023-30253)

Create your malicious engine in seconds