
CVE-2021-4034
Proof-of-concept exploit for CVE-2021-4034, a local privilege escalation in polkit's pkexec, demonstrating exploitation with simple C helpers and a…

Proof-of-concept exploit for CVE-2021-4034, a local privilege escalation in polkit's pkexec, demonstrating exploitation with simple C helpers and a…

This is an implementation of the CVE-2020-0796 aka SMBGhost vulnerability, compatible with the Metasploit Framework

Exploit for CVE-2022-1329, a WordPress Elementor plugin RCE vulnerability, allowing authenticated users to upload and execute arbitrary PHP files via…

CVE-2021-21972 Unauthorized RCE in VMware vCenter metasploit exploit script

Python exploit for CVE-2018-2628 targeting Oracle WebLogic Server deserialization vulnerability. Provides remote code execution against unpatched…

Exploit for CVE-2021-1675 (PrintNightmare) enabling local and remote SYSTEM-level privilege escalation on Windows via the Print Spooler service.…

Exploit for CVE-2018-3252 targeting WebLogic deserialization vulnerability. Includes payload generation with ysoserial and a Python proof-of-concept…

initial exploit for CVE-2019-0708, BlueKeep CVE-2019-0708 BlueKeep RDP Remote Windows Kernel Use After Free The RDP termdd.sys driver improperly…

Annotated FBI exploit for the Tor Browser Bundle from mid-2013 (CVE-2013-1690)

Proof-of-concept exploit for CVE-2022-30333 path traversal in unRAR, generating malicious .rar files to plant payloads at arbitrary locations.…

CVE-2019-0708-EXP(MSF) Vulnerability exploit program for cve-2019-0708

Exploit for CVE-2017-7269, a buffer overflow in IIS 6.0 WebDAV, enabling remote code execution. Designed for use with Metasploit in penetration…

Proof-of-concept exploit for CVE-2026-41651, a Linux local privilege escalation vulnerability in Pack2 software, demonstrating root access and system…

WordPress Backup Guard Authenticated Remote Code Execution Exploit

Exploit for CVE-2022-39197, a cross-site scripting vulnerability in Cobalt Strike's Swing GUI that enables remote code execution on team servers.

The official exploit code for FusionPBX v4.4.8 Remote Code Execution CVE-2019-15029

Remote code execution exploit for Wazuh 8.4 (CVE-2025-24016) with Python-based proof-of-concept targeting vulnerable SIEM deployments.

Pentesting tool integrating Shodan for IP reconnaissance and CVE identification, with Metasploit and Exploit-DB integration for automated exploit…