
ACEDcup
Payload generator for Java Binary Deserialization attack with Commons FileUpload (CVE-2013-2186)

Payload generator for Java Binary Deserialization attack with Commons FileUpload (CVE-2013-2186)

Python exploit script for CVE-2015-6967, enabling authenticated arbitrary file upload in Nibbleblog 4.0.3 with custom payload support.

PowerShell proof-of-concept exploit for CVE-2025-59287 targeting WSUS servers. Automates payload generation with ysoserial.net and triggers a reverse…

Python exploit script for CVE-2019-16113, an authenticated remote code execution vulnerability in Bludit CMS 3.9.2+, with reverse shell payload…

Exploit generator for CVE-2018-15982 (Adobe Flash Player) that produces SWF and HTML files for remote code execution via crafted Flash objects.

Python script exploiting JBoss Java deserialization RCE (CVE-2017-12149) using ysoserial for dynamic payload generation. Requires Java runtime.

Java-based exploit for CVE-2024-21006, delivering a payload via LDAP to a target IP and port. Includes compiled JAR and source for customization.

Proof-of-concept exploit generator for CVE-2017-11882 and CVE-2018-0802, crafting malicious RTF files to execute arbitrary commands on target systems…

Perl-based remote code execution exploit targeting CVE-2018-7600 in Drupal CMS, enabling payload upload and server compromise.

CVE-2023-38831 winrar exploit generator and get reverse shell

Exploit for CVE-2020-17530 (Apache Struts2 S2-061) vulnerability. Provides remote code execution payload generation and testing against vulnerable…

Python exploit suite for CVE-2026-27540, an unauthenticated file upload RCE in the WooCommerce Wholesale Lead Capture plugin, with fingerprinting,…

This Python exploit script targets a vulnerable Laravel Filemanager created by UniSharp, which allows authenticated users to bypass file restrictions…

Proof-of-concept exploit for CVE-2022-30190 (Follina) that generates malicious Word documents with remote payload hosting for calc.exe execution.

Proof-of-concept exploit for CVE-2018-3191 targeting WebLogic Server via JNDI injection. Delivers a JAR payload to trigger remote code execution…

PoC exploit server for CVE-2022-24934 that delivers a malicious payload via a fake WPS Update Server, targeting the wpsupdate.exe process for…

Proof-of-concept scanner targeting CVE-2024-21762 in FortiOS SSL VPN’s /remote/hostcheck_validate endpoint with reverse shell payload delivery.

log4j-paylaod generator : A generic payload generator for Apache log4j RCE CVE-2021-44228