
cve-2019-9081
Exploit for CVE-2019-9081 with payload generation. Pass payload as parameter to trigger the vulnerability.

Exploit for CVE-2019-9081 with payload generation. Pass payload as parameter to trigger the vulnerability.

PoC: Plugin: Zita Site Builder <= 1.0.2 - Arbitrary Plugin Installation

Proof-of-concept exploit for CVE-2018-6574, a remote code execution vulnerability in Go's 'go get' command via malicious package import paths.

Exploit for CVE-2020-35314 delivering a PHP code payload embedded in a ZIP file for web application exploitation.


Exploit for CVE-2024-45507 with a Behinder webshell payload for remote code execution on Apache OFBiz.

Proof-of-concept exploit for CVE-2022-30190, a zero-click remote code execution vulnerability in Microsoft Support Diagnostic Tool (MSDT).

Exploit hook for CVE-2024-32002, a Git remote code execution vulnerability, providing a proof-of-concept implementation.


Proof-of-concept exploit for CVE-2018-6574, a remote code execution vulnerability in Go's net/http package. Demonstrates exploitation of improper…

Exploit script targeting CVE-2017-17058 in WooCommerce, providing a proof-of-concept for remote code execution via crafted requests.

Proof-of-concept for unauthenticated CSV formula injection in SureForms, showing crafted form submissions trigger spreadsheet formulas when exported…

CVE-2026-32475 The Elementor Pro Forms File Upload field handles validation and file processing in two separate loops with different handling of…

Proof-of-concept exploit for CVE-2023-50564 targeting Pluck CMS, delivering a reverse shell via malicious module installation.

Python exploit for Drupal 8 core RESTful API RCE (CVE-2019-6340) that sends crafted requests to execute arbitrary commands on vulnerable sites.

A proof‑of‑concept command‑line tool in C for detecting the SQL injection vulnerability .

Python-based remote code execution exploit targeting WordPress 4.6 via CVE-2016-10033, with reverse shell payload delivery for penetration testing.