
cve-2025-66398
Demonstrate exploitation of Signal K Server CVE-2025-66398 allowing unauthenticated attackers to inject backdoor and enable remote code execution.

Demonstrate exploitation of Signal K Server CVE-2025-66398 allowing unauthenticated attackers to inject backdoor and enable remote code execution.

CVE-2026-33017 - Langflow Unauthenticated RCE Exploit

PHP-based backdoor tool for remote website control via HTTP/HTTPS. Enables file management, command execution, and Tor connectivity with…

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

Python exploit for CVE-2025-57819 targeting FreePBX via unauthenticated SQL injection to achieve remote code execution with automatic reverse shell…

PHP 8.1.0-dev User-Agentt Backdoor Remote Code Execution (RCE)

Proof-of-concept for authenticated OS command injection in TP-Link router firmware. Includes decryption, QEMU-based encryption hook, and 15-character…

Python exploit for CVE-2026-49777, a critical unauthenticated RCE in ShapedPlugin Product Slider Pro for WooCommerce. Includes automated detection…

Multi-CVE exploit tool for pre-auth remote code execution on Ivanti Sentry and FortiSandbox. Features interactive shell, webshell deployment,…

Technical analysis and proof-of-concept for CVE-2026-42167, a critical SQL injection in ProFTPD mod_sql enabling authentication bypass, backdoor user…

POCs to demonstrate CVE-2026-42167 in ProFTPD

LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole…

Escaner de identificacion de vulnerabilidades para CVE-2025-4322

Unauthenticated RCE via Webmin Backdoor (CVE-2019–15107)

PoC Docker lab: chaining file upload bypass + stored XSS to create admin accounts. Educational resource for pen testers.

Proof-of-concept exploit for CVE-2026-30345, an arbitrary file write in CTFd backup import, enabling persistent backdoor via .bashrc.

CVE-2025-66398 — Signal K Server ≤ 2.18.0 RCE PoC