
CVE-2026-60004-PoC
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Exploit for CVE-2026-41940 providing direct shell access via websocket and persistence through root API key injection.

Simple PHP reverse shell script for establishing remote command execution on target systems. Ideal for penetration testing and security assessments.

Reproduces ZendTo unauthenticated ClamAV RCE and root privilege escalation in an authorized lab, with pinned Docker target, fail-closed verification,…

Never forget where you inject.

WhiteWinterWolf's PHP web shell

This script automates SQL injection testing using SQLMap with AI-powered decision making.

WordPress Core Pre-Auth RCE — Batch Route Confusion + SQL Injection

Web vulnerability scanner focused on automated XSS/CSP bypass payload testing and batch SQL injection detection, using SQLMap and reporting only…

A proof-of-concept for CVE-2026-39987

Authenticated Blind OS Command Injection in ClearOS

Know a plugin has a php object exploit but need to find which lib to use?

PHP script that establishes a reverse shell from a target server to the attacker's machine, enabling remote command execution and post-exploitation…

Plugin For BurpSuite (Pentester)

pluck CMS 4.7.18 is affected by a Multiple Stored Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a…

Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.

Demo project how to bypass the disable_functions security control of PHP on Linux

That repository contains my updates to the well know java deserialization exploitation tool ysoserial.