
CVE-2024-9264-Fixed
Fixed proof-of-concept exploit for CVE-2024-9264, a critical Grafana RCE via DuckDB SQL expressions. Executes reverse shell using corrected shellfs…

Fixed proof-of-concept exploit for CVE-2024-9264, a critical Grafana RCE via DuckDB SQL expressions. Executes reverse shell using corrected shellfs…

Docker-based lab environment demonstrating CVE-2018-19518 RCE exploit via PHP IMAP extension, with step-by-step usage and WAF integration for…

AdmirorFrames Joomla! Extension < 5.0 - Server-Side Request Forgery

Proof-of-concept exploit for CVE-2021-40905, a remote code execution vulnerability in CheckMK Management Web Console via crafted .mkp extension…

AdmirorFrames Joomla! Extension < 5.0 - HTML Injection

Educational lab demonstrating CVE-2017-8291 (PIL/GhostScript RCE) via crafted EPS file upload with PNG extension, including Docker setup and PoC…

ImaegMagick Code Execution (CVE-2016-3714)

POC exploit for CVE-2015-10141

CVE-2026-48907 – Joomla JCE Unauthenticated Remote Code Execution (RCE)

Proof of concept and technical write-up for CVE-2026-56096, a blind Solr query injection in TYPO3 EXT:solr enabling unauthenticated field enumeration…

A stored cross-site scripting (XSS) vulnerability exists in OpenKM version 7.1.40.

Python exploit for RCE in Wordpress

Mautic < 5.2.3 Authenticated RCE

PoC funcional de CVE-2026-45247: PHP Object Injection a RCE no autenticado en Mirasvit Full Page Cache (Magento 2).

Responsive FileManager v.9.9.5 vulnerable to CVE-2022-46604.

This tool is a Proof of Concept (PoC) intended for security research and educational purposes only. Using this tool on systems without explicit…

Exploit for CVE-2026-17544: PHP bcmath OOB write converted into memory-only RCE, bypassing disable_functions and open_basedir with a runtime…

PoC exploit for CVE-2026-17543: SQL injection in PHP ext/pgsql via backslash breakout, with data exfiltration and admin privilege-escalation payloads…