
CVE-2020-17530-s2-061
GUI-based exploit for CVE-2020-17530 (Apache Struts2 S2-061) with built-in reverse shell function for educational and penetration testing purposes.

GUI-based exploit for CVE-2020-17530 (Apache Struts2 S2-061) with built-in reverse shell function for educational and penetration testing purposes.

Proof-of-concept for authenticated arbitrary file upload in Sitecore 10.3, enabling webshell deployment and remote code execution via the import…

Proof-of-concept exploit for CVE-2022-30190 (Follina). Generates malicious docx files and hosts a server to trigger remote code execution via…

Python exploit for CVE-2022-22965 (Spring4Shell) RCE vulnerability in Java Spring Core. Injects a JSP webshell via Tomcat log configuration to…

Proof-of-concept exploit for CVE-2023-30800, demonstrating a web application vulnerability with a Go-based payload generator for security testing and…

Python-based exploit generator for CVE-2018-8174, producing malicious RTF files delivered via HTML pages with reverse shell callback capability.

Python exploit script for CVE-2024-25180, a remote code execution vulnerability in pdfmake, delivering a reverse shell via crafted POST requests.

Python exploit for CVE-2023-45878 targeting Gibbon LMS 25.0.1. Uses arbitrary file write to upload a PHP web shell and execute a PowerShell reverse…

Proof-of-concept for a stored Cross-Site Scripting (XSS) vulnerability in Pluck CMS 4.7.18 installation. Injects payload via cont1 and cont2…

Exploit module for FreePBX delivering a reverse shell payload to achieve remote command execution and persistent shell access, designed for…

Proof-of-concept exploit for an unauthenticated arbitrary file upload vulnerability in the WordPress Instant Appointment plugin, enabling remote code…

Exploit for CVE-2021-26084, a remote code execution vulnerability in Confluence Server, allowing unauthenticated attackers to execute arbitrary code.

Exploit for CVE-2021-22005 targeting vCenter Server arbitrary file upload vulnerability, enabling direct webshell deployment for post-exploitation…

Proof-of-concept exploit for CVE-2018-6574, a remote code execution vulnerability in Go's 'go get' command. Demonstrates injection via malicious…

Proof-of-concept exploit for CVE-2021-44228 (Log4Shell) enabling remote code execution via JNDI injection in Apache Log4j.

Python-based proof-of-concept exploit for CVE-2018-13382, demonstrating the vulnerability with a functional PoC script for security testing and…

Node.js reverse shell payload generator for penetration testing. Creates bind and reverse shells in JavaScript.

Automated PoC scanner for CVE-2025-29927 Next.js middleware bypass vulnerability. Tests multiple x-middleware-subrequest payloads across target URLs…