
CVE-2020-9484
Bash proof-of-concept exploit for CVE-2020-9484 enabling remote code execution on Apache Tomcat via insecure deserialization in file uploads, with…

Bash proof-of-concept exploit for CVE-2020-9484 enabling remote code execution on Apache Tomcat via insecure deserialization in file uploads, with…

Rejetto http File Server 2.3.x (Reverse shell)

Proof-of-concept exploit for CVE-2022-26134 (OGNL injection in Atlassian Confluence). Provides reverse shell and in-memory file reader for Linux…

MySQL-Fu is a Ruby based MySQL Client Script I wrote. It does most of the stuff a normal MySQL client might do: SQL Shell, Update/Delete/Drop…

Python-based exploit for CVE-2014-6287 in HTTP File Server 2.3.x, delivering a reverse shell via Base64-encoded PowerShell payload for authorized…

Exploit for CVE-2009-4623: remote file inclusion in Advanced Comment System 1.0 enabling arbitrary PHP code execution and reverse shell via ACS_path…

Proof-of-concept scripts for CVE-2023-1389, an unauthenticated command injection in TP-Link Archer AX21, providing file transfer and reverse shell…

Authenticated RCE exploit PoC and vulnerability scanner for CVE-2025-68613 in n8n. Supports command execution, file operations, and reverse shell…

WordPress Backup Guard Authenticated Remote Code Execution Exploit

PoC Script for CVE-2024-25832: Exploit chain reverse shell, information disclosure (root password leak) + unrestricted file upload in DataCube3

Unauthenticated arbitrary file upload exploit for Realtyna WPL/Organic IDX WordPress plugin, chains PHP webshell upload to RCE, with command…

Proof-of-concept exploit for CVE-2026-54806: unauthenticated PHP object injection in WP Activity Log plugin enabling blind RCE via User-Agent header.…

Automated PoC exploit for CVE-2026-6009, a Java deserialization RCE in Jaspersoft Reports <=7.0.3. Generates malicious .jasper payloads via ysoserial…

Proof-of-concept exploit for CVE-2026-0766, a remote code execution vulnerability in OpenWebUI via tool code injection. Includes command execution,…

Proof-of-concept exploit for CVE-2023-45158, a command injection vulnerability in web2py. Demonstrates remote code execution via crafted HTTP…

Python exploit for CVE-2023-4220 in Chamilo LMS that uploads a file and delivers an unauthenticated reverse shell to a netcat listener.

Proof-of-concept exploit for authenticated remote code execution in Krayin CRM v2.2.x via unrestricted file upload, supporting web shell and reverse…

Proof-of-concept demonstrating remote code execution via prompt injection in GitHub Copilot Chat, using a crafted Python file to trigger a…