
CVE-2024-10924-Exploit
Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass

Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass

This small script helps to avoid using MetaSploit (msfconsole) during the Enterprise pentests and OSCP-like exams. Grep included function will help…

Spring Framework RCE (CVE-2022-22965) Nmap (NSE) Checker (Non-Intrusive)

PoC of Remote Command Execution via Log injection on SAP NetWeaver AS JAVA CRM

Apache struts struts 2 048, CVE-2017-9791.

Proof-of-concept exploit for CVE-2022-0332, a SQL injection vulnerability in Moodle 3.11 to 3.11.4, with a working HTTP GET payload for…

test struts2 vulnerability CVE-2017-5638 in Mac OS X

test for CVE-2018-6574: go get RCE pentesterlab

Exploit for CVE-2025-64512 to get a reverse shell.

Exploit for remote command execution in Golang go get command.

Exploit for CVE-2022-46169

Proof-of-concept exploit for CVE-2022-22954, a server-side template injection in VMware Workspace ONE Access Freemarker, enabling remote code…

An exploit for Four-Faith routers to get a reverse shell

RCE exploit for AVideo < 8.9 (CVE-2020-23489 & CVE-2020-23490)

Python-based exploit for CVE-2017-8056 targeting XML-RPC denial-of-service vulnerability in web applications.

Proof-of-concept exploit for CVE-2022-22954, a Freemarker server-side template injection in VMware Workspace ONE Access, with a one-line GET request…

Proof-of-concept for time-based blind SQL injection in a PHP admin panel. Demonstrates exploitation via unsanitized GET parameter, with mitigation…

PoC payload generator for CVE-2022-44268 ImageMagick arbitrary file read vulnerability. Demonstrates exploitation via crafted PNG files for…