
CVE-2024-44541
This repository details a SQL Injection vulnerability in Inventio Lite v4's, including exploitation steps and a Python script to automate the attack.…

This repository details a SQL Injection vulnerability in Inventio Lite v4's, including exploitation steps and a Python script to automate the attack.…

The vulnerable application that will teach you how to hack WebSockets

A simple demo application that shows how to reproduce the Ivanti EPMM pre-auth RCE vulnerability (CVE-2026-1281 / CVE-2026-1340) for educational and…

Proof-of-concept exploit for CSRF to RCE in Backdrop CMS 1.20 (CVE-2021-45268) using malicious plugin upload.

Python PoC script exploiting an arbitrary file upload vulnerability in Best House Rental Management System 1.0 to upload a PHP web shell and execute…

Python exploit for CVE-2022-32199, enabling authenticated admin users to delete arbitrary files on ScriptCase <= 9.9.008 via directory traversal.

Generates malicious RAR archives automatically to exploit CVE-2018-20250 and achieve code execution via WinRAR ACE path traversal.

Python exploit script for CVE-2018-20250 that generates a malicious RAR archive to achieve code execution via WinRAR's ACE file extraction…

Python exploit script for CVE-2026-23744 that delivers a reverse shell to a specified target URL, requiring a netcat listener for command-and-control.

exp for https://research.checkpoint.com/extracting-code-execution-from-winrar

A step by step workshop to exploit various vulnerabilities in Node.js and Java applications

[NEW] : Mega Bot ☣ Scanner & Auto Exploiter

Primefaces <= 5.2.21, 5.3.8 or 6.0 - Remote Code Execution Exploit

jenkins CVE-2017-1000353 POC


Proof-of-concept exploit for CVE-2026-1010, demonstrating WebSocket connection smuggling and request splitting through a malformed Upgrade header…

Proof-of-concept exploit for CVE-2024-2961, leveraging iconv encoding flaws and PHP filter chains to read arbitrary files from vulnerable servers via…

Exploit created by: R4v3nBl4ck end Pacman