
Project-CVE-2026-33017
CVE-2026-33017 - Langflow Unauthenticated RCE Exploit

CVE-2026-33017 - Langflow Unauthenticated RCE Exploit

Proof-of-concept exploit for CVE-2026-30345, an arbitrary file write in CTFd backup import, enabling persistent backdoor via .bashrc.

OS Command Injection Vulnerability via Cache Clearing Scheduler in Reolink Desktop Application

Technical analysis and proof-of-concept for CVE-2026-42167, a critical SQL injection in ProFTPD mod_sql enabling authentication bypass, backdoor user…

Explanation and payload of the recent vulnerability in the LA-Studio Element WordPress plugin.

Proof-of-concept exploit for CVE-2026-0920 in LA-Studio Element Kit, enabling unauthenticated privilege escalation to administrator via crafted AJAX…

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

Proof-of-concept exploit and analysis for command injection and hardcoded backdoor credentials in D-Link NAS devices, enabling unauthenticated remote…

JSP-less Java Servlets Backdoor inspired by https://www.redteam-pentesting.de/files/redteam-jboss.tar.gz

A list of custom Metasploit modules you can use for penetration testing.

PHP 8.1.0-dev WebShell Remote Code Execution

Proof-of-concept exploit and vulnerability disclosure for HiSilicon hi3520d DVR/NVR devices. Demonstrates RCE via web interface, backdoor…

WonderCMS Plugin

PHP 8.1.0-dev Backdoor System Shell Script

LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole…

PHP 8.1.0-dev User-Agentt Backdoor Remote Code Execution (RCE)

phpstudy dll backdoor for v2016 and v2018