
CVE-2025-10230
Proof-of-concept exploit for CVE-2025-10230, a Samba WINS hook command injection vulnerability, demonstrating limited 15-character command execution.

Proof-of-concept exploit for CVE-2025-10230, a Samba WINS hook command injection vulnerability, demonstrating limited 15-character command execution.

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

CVE-2026-60004 — Gitea Pre-Auth RCE via diffpatch hook injection

Proof-of-concept exploit for CVE-2026-26216, demonstrating unauthenticated remote code execution via hook injection in Crawl4AI's Docker deployment.…

Automated proof-of-concept exploit for CVE-2026-60004, a Gitea diffpatch Git hook RCE that plants a post-index-change hook to gain a reverse shell as…

Proof-of-concept exploit for CVE-2026-54088, a pre-authentication OS command injection in File Browser <=2.63.5. Demonstrates shell injection via…

Proof-of-concept exploit for CVE-2025-8110, a command injection vulnerability in Gogs Git hook mechanism enabling remote code execution on…

Exploit for CVE-2024-32002 targeting Git hook vulnerabilities, enabling remote code execution via crafted repositories during clone operations.

RCE hook

hook repo for cve-2024-32002

Proof-of-concept exploit for CVE-2024-32002, a Git RCE via crafted submodules on case-insensitive filesystems, demonstrating malicious hook execution…

Exploit hook for CVE-2024-32002, a Git remote code execution vulnerability, providing a proof-of-concept implementation.

Authenticated remote code execution exploit for CERIO routers (DT300N, DT100G, AMR-3204, WMR-200N) using vendor default credentials. Python PoC…


Cloudflare Image Resizing <= 1.5.6 | Unauthenticated Remote Code Execution

CERIO RCE CVE-2018-18852, authenticated (vendor defaults) web-based RCE as root user.

Proof of Concept for CVE-2024-32002

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass