
CVE-2025-3616
Metasploit module exploiting arbitrary file upload in Greenshift WordPress plugin (CVE-2025-3616) to achieve RCE via MIME spoofing, with…

Metasploit module exploiting arbitrary file upload in Greenshift WordPress plugin (CVE-2025-3616) to achieve RCE via MIME spoofing, with…

This repository contains a Metasploit module implementation for the MS08-067 Windows Server Service vulnerability (CVE-2008-4250). This is a classic…

Exploit for CVE-2020-6418, a type confusion in V8, allowing remote code execution via crafted HTML page. Uses Metasploit to deliver a reverse shell…

Metasploit module for exploiting CVE-2017-11882 (MS Office Equation Editor vulnerability) using mshta.exe payload execution for remote code execution.

Exploit code for CVE-2025-31324, providing proof-of-concept and automated exploitation for the identified vulnerability.

Metasploit Modules

GitStackRCE漏洞(CVE-2018-5955)EXP

Just a couple exploits for CVE-2018-11510

Exploit for CVE-2018-2628, a Java deserialization vulnerability in Oracle WebLogic Server, enabling remote code execution.

Metasploit module that exploits a WordPress unserialization vulnerability (CVE-2024-31211) in WP_HTML_Token to achieve remote code execution.

Metasploit module for Apache Struts CVE-2017-9791 Remote Code Execution Vulnerability

Generates malicious RAR archives exploiting a path traversal vulnerability in unRAR to plant files at arbitrary locations, demonstrated with a Zimbra…

Metasploit module generating a malicious Word document to exploit CVE-2018-8174, a VBScript memory corruption vulnerability in Microsoft Office…

Atmail XSS-CSRF-RCE Exploit Chain

Modified version of auxiliary/admin/http/tomcat_ghostcat, it can Read any file

Metasploit module exploiting CVE-2022-28108 in Selenium Grid for remote code execution, with content-type evasion and post-exploitation capabilities.

Metasploit exploit module for CVE-2024-6366, an unauthenticated file upload remote code execution in WordPress User Profile Builder before 3.11.8,…

Description of Exploit SMBGhost CVE-2020-0796