
CVE-2026-23744-PoC
Proof-of-concept exploit for CVE-2026-23744, targeting /api/mcp/connect to achieve remote command execution on Linux systems via reverse shell.

Proof-of-concept exploit for CVE-2026-23744, targeting /api/mcp/connect to achieve remote command execution on Linux systems via reverse shell.

Cross-platform remote code execution exploit for GNU Inetutils telnet (versions 1.9.3 to 2.7), targeting CVE-2026-24061 with a simple command-line…

Proof-of-concept exploit for time-based blind SQL injection in Commend VoIPRec G8-VOIPREC device, targeting the vulnerable Code parameter for…

Exploit for Fastjson RCE (CVE-2026-16723) targeting versions 1.2.68 to 1.2.83. Generates JAR and JSON payloads, hosts HTTP server, and establishes…

Python-based exploit for CVE-2025-30208 targeting Vite dev server arbitrary file read. Supports single-target detection, custom file paths, system…

Exploit for CVE-2023-4427 targeting Chrome 117 V8, using many cross-origin iframes to brute-force ASLR and achieve code execution. Provides…

Golang PoC exploit for CVE-2025-12139 targeting the Integrate Google Drive WordPress plugin. Extracts sensitive OAuth credentials (Client ID, Secret,…

Mass RCE exploit script for CVE-2025-55182 (React2Shell) targeting Next.js applications. Automates payload injection, command execution, and output…

Full exploit for CVE-2019-13764 targeting V8 JavaScript engine on Linux, with root cause analysis and proof-of-concept code from Haboob Research Team.

CVE-2025-55182 payload

Local lab and proof-of-concept exploit for CVE-2025-27407, targeting GitLab's GraphQL introspection schema loader via the Direct Transfer HTTP path.…

proof-of-concept mass scanner targeting JetBrains TeamCity instances affected by CVE-2024-27198

Reflected cross-site scripting (XSS) proof-of-concept exploit for CVE-2023-29808 targeting the /index.php?map=overview&findme= endpoint in cmaps…

Proof-of-concept exploit for CVE-2023-20198 targeting Cisco IOS XE Web UI. Enables unauthenticated remote command execution, configuration retrieval,…

Python exploit for CVE-2020-9047 targeting exacqVision Web Service. Supports Windows/Linux payload delivery, remote command execution, and…

Python exploit for CVE-2019-11043 targeting PHP-FPM buffer underflow to achieve remote code execution via null byte overwrite and FastCGI variable…

Educational exploit for CVE-2015-0311, a use-after-free vulnerability in Adobe Flash Player, targeting Linux/Firefox to demonstrate memory corruption…

Python-based exploit for CVE-2017-8056 targeting XML-RPC denial-of-service vulnerability in web applications.