
deep-C
Android deeplink misconfiguration detector and exploitation tool

Android deeplink misconfiguration detector and exploitation tool

Proof-of-concept exploit chaining four CVEs (CVE-2023-36844-47) for pre-authentication remote code execution on Juniper JunOS SRX and EX series…

CVE-2024-41570: Havoc C2 0.7 Teamserver SSRF exploit

ASPX web shell with COFF loader for executing Beacon Object Files (BOFs) on target servers via a semi-interactive Python client, designed for…

Proof-of-concept exploit for CVE-2020-2551, demonstrating remote code execution in Oracle WebLogic Server via the IIOP protocol. Includes default…

Proof-of-concept exploit for CVE-2022-23808, a stored XSS vulnerability in phpMyAdmin 5.1.1 setup script, with payload and reproduction steps for…

This is the Pwn2Own 2017 Safari backup vul's exploit.

Go-based proof-of-concept exploit for CVE-2022-23131, a Zabbix SAML authentication bypass. Enables unauthorized admin access by forging SAML…

CVE-2026-8452 PreAuth RCE

Exploiting CVE-2021-44228 in VMWare Horizon for remote code execution and more.

A critical vulnerability, CVE-2024-53677, has been identified in the popular Apache Struts framework, potentially allowing attackers to execute…

Fortinet Fortimanager Unauthenticated Remote Code Execution AKA FortiJump CVE-2024-47575

CVE-2018-17246 - Kibana LFI < 6.4.3 & 5.6.13

Proof-of-concept exploit for CVE-2023-25194, a JNDI injection vulnerability in Apache Kafka Connect enabling remote code execution via crafted…

PHP 8.1.0-dev Backdoor System Shell Script

Confluence未授权添加管理员用户(CVE-2023-22515)漏洞利用工具

Clawdbot/Moltbot/OpenClaw One-click RCE PoC 🦞 (CVE-2026-25253)

Exploit for CVE-2025-25257, a FortiWeb Fabric RCE vulnerability, with a full working exploit and a PoC for file read/write.