
CVE-2019-15029
The official exploit code for FusionPBX v4.4.8 Remote Code Execution CVE-2019-15029

The official exploit code for FusionPBX v4.4.8 Remote Code Execution CVE-2019-15029

[CVE-2020-17519] Apache Flink RESTful API Arbitrary File Read

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

Proof-of-concept exploit and Metasploit module for CVE-2015-2900 targeting the MEDCIN Engine (medcinserv.exe) versions prior to 2.22.20142.166.

Metasploit module & Python script for CVE-2019-16405

Metasploit module exploiting InfoBlox Network Automation CVE-2014-3418 command injection to create a sudo user and deliver a reverse Meterpreter…

ShadowRay RCE POC (CVE-2023-48022)

Crestron/Barco/Extron/InFocus/TeqAV Remote Command Injection (CVE-2019-3929) Metasploit Module

A list of custom Metasploit modules you can use for penetration testing.

CVE-2019-0708 With Metasploit-Framework Exploit

React2Shell - CVE-2025-66478 RCE Exploit

CVE-2021-31166: exploitation with Powershell, Python, Ruby, NMAP and Metasploit.

PoC for Webmin Package Update Authenticated Remote Command Execution

Apache HTTP Server 2.4.x mod_lua Buffer Overflow (CVE-2021-44790) - Advanced exploitation framework with fingerprinting, multi-stage scanning, plugin…

Python exploit for CVE-2026-49083 targeting privilege escalation in the LatePoint Calendar Booking WordPress plugin. Provides automated exploitation…

Exploit toolkit CVE-2017-0199 - v2.0 is a handy python script which provides a quick and effective way to exploit Microsoft RTF RCE. It could…

Metasploit module that exploits Apache HTTP Server SSRF (CVE-2024-38472) on Windows to reach internal services and achieve remote code execution.

Python exploit for CVE-2026-49083, a privilege escalation vulnerability in the LatePoint Calendar Booking WordPress plugin, enabling unauthorized…