
exchange_proxylogon
Module pack for #ProxyLogon (part. of my contribute for Metasploit-Framework) [CVE-2021-26855 && CVE-2021-27065]

Module pack for #ProxyLogon (part. of my contribute for Metasploit-Framework) [CVE-2021-26855 && CVE-2021-27065]

Unrestricted file upload vulnerability - Web Viewer 1.0.0.193 on Samsung SRN-1670D

Know a plugin has a php object exploit but need to find which lib to use?

Modification of Metasploit module for RCE in Ruby-On-Rails Console CVE-2015-3224

Authenticated Blind OS Command Injection in ClearOS

Reproduces ZendTo unauthenticated ClamAV RCE and root privilege escalation in an authorized lab, with pinned Docker target, fail-closed verification,…

WordPress Core Pre-Auth RCE — Batch Route Confusion + SQL Injection

Penetration test of a Drupal web app — CVE-2018-7600 (Drupalgeddon 2) exploited using Nmap, Burp Suite & Metasploit | Internship @ BB CyberSec

A proof-of-concept for CVE-2026-39987

Exploit for CVE-2026-41940 providing direct shell access via websocket and persistence through root API key injection.

Metasploit module for WordPress DOS load-scripts.php CVE-2018-638

Educational proof-of-concept demonstrating how to embed a Meterpreter backdoor into a PDF file exploiting CVE-2010-1240, with step-by-step Metasploit…

The CSRF Exploit Generator allows users to generate a CSRF exploit form with configurable parameters.

This Metasploit module exploits an unauthenticated remote code execution vulnerability which exists in Apache version 2.4.49 (CVE-2021-41773). If…

this is a metasploit exploit module for CVE-2024-25096 and CVE-2023-3452

Metasploit module for MailEnable CVE-2022-36934 authentication bypass RCE

Authenticated command injection exploit for QuickBox Pro v2.1.8, providing remote code execution as www-data and privilege escalation to root via…

This framework is designed to assist penetration testers or developers in understanding the mechanics of remote code execution (RCE) exploitation.