
CVE-2021-43008-AdminerRead
Exploit tool for CVE-2021-43008 Adminer 1.0 up to 4.6.2 Arbitrary File Read vulnerability

Exploit tool for CVE-2021-43008 Adminer 1.0 up to 4.6.2 Arbitrary File Read vulnerability

Proof-of-concept exploit for CVE-2022-30190 (Follina) that generates malicious Word documents with remote payload hosting for calc.exe execution.

MDJM Event Management <= 1.7.8.3 - Authenticated (Administrator+) Arbitrary File Upload via 'mdjm_email_upload_file' Parameter

Kalrav AI Agent <= 2.3.3 - Unauthenticated Arbitrary File Upload via kalrav_upload_file AJAX Action

HikVision Auth Bypass CVE, tool is able to extract credentials, and take snapshots based on magic cookie or supplied credentials.

Documentation of a denial-of-service vulnerability in the Rizin reverse engineering framework's ELF parser, caused by a forged DT_VERNEEDNUM value…

Exploit for CVE-2023-23397 Outlook NTLM hash leak via malicious calendar invitations. Includes PowerShell weaponization, Responder integration, and…

CVE-2025-24071 Proof Of Concept

Proof-of-concept exploit for CVE-2025-8081, an arbitrary file read in Elementor WordPress plugin, allowing authenticated admins to read sensitive…

Writeup och POC för CVE-2008-2992

Jenkins POC of Arbitrary file read vulnerability through the CLI can lead to RCE

A "Exposed Dangerous Method or Function" or "Use of Hard-coded, Security-relevant Constants" vulnerability in PrintixService.exe, in Kofax Printix's…

Python exploit for CVE-2020-29607 that bypasses file upload restrictions in Pluck CMS to upload a PHP webshell, enabling remote command execution on…

Python script that generates a malicious RAR file exploiting CVE-2023-38831 to execute a reverse shell payload, intended for educational and ethical…

Quick test for CVE-2023-26025 behaviours

Educational exploit for CVE-2022-2588, a Linux kernel race condition leading to privilege escalation. Includes Vagrant setup for a vulnerable machine…

Proof-of-concept demonstrating CVE-2007-4559 path traversal in Python's tarfile module, allowing arbitrary file overwrite via malicious TAR archives.

Bash script to detect and exploit CVE-2022-44877 command injection vulnerability in CentOS Web Panel, supporting single URL scanning, exploitation,…