
CVE-2026-44011-craft-rce-poc
Python proof-of-concept for CVE-2026-44011 in Craft CMS, exploiting authenticated remote code execution with command execution and base64-wrapped…

Python proof-of-concept for CVE-2026-44011 in Craft CMS, exploiting authenticated remote code execution with command execution and base64-wrapped…

Python PoC exploiting CVE-2025-27636, an Apache Camel header injection RCE, supporting command execution, file reads, and reverse shell payloads.

Proof of Concept (PoC) for CVE-2022-42889 (Text4Shell) targeting Apache Commons Text versions prior to 1.10.0. This script automates Remote Code…

Python exploit script for CVE-2021-21425 targeting Grav CMS admin panel, delivering a reverse shell via HTTP POST request with configurable LHOST and…

CVE-2023-46604-RCE exploit with Linux reverse shell payload

Exploit for CVE-2024-37054: generates a malicious pickle model, uploads it to MLflow, and triggers remote code execution via the /predict endpoint.

Authenticated RCE PoC for Flowise version <= 3.0.5 via CustomMCP Node (CVE-2025-59528)

Python exploit for CVE-2025-6002 targeting authenticated arbitrary file upload in VirtueMart < 4.4.10. Logs in, uploads a PHP webshell, and triggers…

CVE-2025-49844

Automated exploit for CVE-2025-49132, a critical unauthenticated RCE in Pterodactyl Panel. Leverages LFI via locale endpoint to deploy persistent web…

Automated proof-of-concept exploit for CVE-2023-4220 in Chamilo LMS, enabling arbitrary file upload and remote code execution via unauthenticated…

IBM i DDM Unauthenticated RCE - Java Reverse Shell

Proof-of-concept exploit for CVE-2025-55182, demonstrating remote code execution via a React-based application to achieve a reverse shell.

Detects and exploits CVE-2024-21762 pre-authentication RCE in FortiGate SSL VPN, featuring baseline validation, automatic exploitation, ROP…

This script exploits CVE-2025-62369 in Xibo CMS to execute a reverse shell command.

Exploit for CVE-2025-55182 targeting React applications, delivering a reverse shell payload for penetration testing and security research.

POC exploit for Dolibarr <= 17.0.0 (CVE-2023-30253)

Proof of Concept for Authenticated RCE in Crafty Controller <= 4.6.1