
CVE-2026-75604-poc
Proof-of-concept exploit for CVE-2026-75604, an unauthenticated remote code execution in Windows-hosted Next.js apps, with callback-based command…

Proof-of-concept exploit for CVE-2026-75604, an unauthenticated remote code execution in Windows-hosted Next.js apps, with callback-based command…

CVE-2026-0073 - ADB Wireless Mutual Authentication Bypass PoC

spring4shell | CVE-2022-22965

This exploit is based on CVE-2017-9757 and was built upon the original exploit by 0x09AL.

Adobe Magento SessionReaper LFI Vulnerability

Exploit Title: Unauthenticated SQL Injection on CMS Made Simple <= 2.2.9

Proof-of-concept exploit for CVE-2026-75604, an unauthenticated RCE in Windows-hosted Next.js via cache path traversal and forged Server Action, for…

Automated proof-of-concept for authenticated remote code execution in WordPress File Manager Pro (Filester) via arbitrary file upload, including…

CVE-2023-46604-RCE exploit with Linux reverse shell payload

CVE-2023-38831 (PoC) - WinRAR Exploit

CVE-2022-0169 - WordPress Photo Gallery SQLi PoC

This repository includes two PoC scripts for CVE-2025-57819 in FreePBX: one to create a new admin user (poc_admin.py), and another to extract…

Unauthenticated Privilege Escalation

Real Estate 7 <= 3.5.2 - Unauthenticated Privilege Escalation

One-shot exploit for Gogs symlink RCE (CVE-2025-8110) that triggers a reverse shell via a single PUT request to UpdateRepoFile.

This exploit is based on CVE-2019-6340 and was built upon the original exploit by leonjza and the Metasploit module, extending it can be executed…

Proof-of-concept exploit for CVE-2024-34070, a stored XSS in Froxlor. Detects vulnerable instances, extracts version, and injects payload to create…