
CVE-2023-27372-POC
Python proof-of-concept for detecting CVE-2023-27372 in SPIP CMS. Scans single or multiple URLs for the vulnerability and outputs results to terminal…

Python proof-of-concept for detecting CVE-2023-27372 in SPIP CMS. Scans single or multiple URLs for the vulnerability and outputs results to terminal…

CVE-2022-22963 RCE PoC in python

Python exploit for CVE-2022-22963 (Spring4Shell) targeting Spring Cloud Function RCE. Automates reverse shell delivery via wget and bash one-liner…

CVE-2024-9264 Grafana SQL Expressions DuckDB LFI/RCE PoC

Python PoC for CVE-2025-55182 (React2Shell) RCE in Next.js/React Server Components with dynamic WAF bypass padding for authorized security testing.

Python PoC exploit for CVE-2025-8018, a critical unauthenticated SQL injection in Food Ordering Review System v1.0. Supports time-based blind and…

Python proof-of-concept for CVE-2026-5615, a stored XSS in VvvebJs, demonstrating SVG upload exploitation with multi-threaded scanning and validation.

CVE-2025-59528 Proof of Concept

Python proof-of-concept for CVE-2026-3844, an unauthenticated arbitrary file upload in WordPress Breeze Cache plugin, enabling remote code execution.…

CVE-2025-58434 Proof of Concept

Python PoC exploit for CVE-2023-6329 authentication bypass in Control iD iDSecure. Reconstructs admin credentials via predictable password derivation…

This exploit is based on CVE-2023-26360 (https://nvd.nist.gov/vuln/detail/CVE-2023-26360) and was built on top of the Metasploit module and the…

Proof of Concept for CVE-2021-29447 written in Python

Python PoC for Webmin 1.580 Remote Command Execution (CVE-2012-2982)

Python PoC for CVE-2023-46818

Exploit for CVE-2024-4040 – Authentication bypass in CrushFTP via CrushAuth cookie and AWS-style header spoofing. Stealthy Python PoC with secure…

Python PoC exploit for CVE-2015-3306 ProFTPD directory traversal. Copies files and drops a PHP backdoor into webroot for remote command execution via…

Python proof-of-concept for testing SMTP command injection (CVE-2026-73570) by sending malformed RCPT TO addresses to detect shell command…