
Apache-couchdb-CVE-2017-12635
Docker-based reproduction environment for Apache CouchDB CVE-2017-12635 vertical privilege escalation via JSON parser inconsistency, enabling…

Docker-based reproduction environment for Apache CouchDB CVE-2017-12635 vertical privilege escalation via JSON parser inconsistency, enabling…

Exploit for CVE-2025-50505 in Clash Verge Rev, demonstrating local privilege escalation and remote code execution via unauthenticated API, including…

Hands-on exploit lab for CVE-2024-28000 — unauthenticated privilege escalation in LiteSpeed Cache (WordPress plugin, <=6.3.0.1). Spins up a…

From XSS to RCE 2.75 - Black Hat Europe Arsenal 2017 + Extras

SQL Injection Vulnerability in Vehicle Management System 1.0 - 1.3

Post-authentication reverse shell exploit for Webmin <=1.984 leveraging CVE-2022-0824 File Manager privilege escalation. Downloads and executes a CGI…

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

playSMS < = 1.4.2 - Privilege escalation

WordPress Pie Register ≤ 3.7.1.4 - Admin Privilege Escalation (Unauthenticated)

WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation

An issue in the password reset function of Peppermint v0.2.4 allows attackers to access the emails and passwords of the Tickets page via a crafted…

CVE-2023-20198-RCE, support adding/deleting users and executing cli commands/system commands.

Unauthenticated Privilege Escalation via Account Takeover

School Fees Management System v1.0 - Incorrect Access Control - Privilege Escalation

Proof-of-concept exploit for Microsoft Exchange Server Remote Code Execution via ACL bypass, privilege escalation, and arbitrary file write…

Advanced Custom Fields: Extended <= 0.9.2.5 - Unauthenticated Privilege Escalation via Validation Bypass to '_acf_post_id' Parameter

PoC of CVE-2025-46203

Python exploit script for CVE-2025-2304, a mass assignment privilege escalation in Camaleon CMS. Automates CSRF token parsing and role parameter…