
CVE-2024-42992
CVE-2024-42992

CVE-2024-42992

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

Python exploit for CVE-2018-7600 enabling unauthenticated remote code execution on Drupal 7.x versions below 7.58.

CVE-2018-8581 | Microsoft Exchange Server Elevation of Privilege Vulnerability

Exploit script for CVE-2021-4191 that enumerates GitLab users via the GraphQL API, useful for security assessments and validating exposure.

Proof-of-concept exploit for CVE-2026-21440, enabling file upload and remote command execution on Windows web servers with built-in sensitive path…

Handlebars Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability

Exploit script for CVE-2017-9841 targeting PHP unit test remote code execution. Includes a local test environment via Docker for educational security…

An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the Cmd parameter.

Exploit script for CVE-2023-27372 targeting SPIP CMS, enabling remote code execution for authorized security testing and educational purposes.

An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the…

Testing and exploitation tool for Drupalgeddon 2 (CVE-2018-7600)

Remote Code Execution via n8n Workflows (Based on CVE-2025-68613)

Exploit for MCPJam Inspector <=1.4.2 that triggers remote code execution via crafted HTTP requests, enabling unauthorized installation of MCP servers…


This is a python written PoC of a recent vulnerability in a wordpress plugin. More information on that here

CVE-2023-30990 exploits

Python exploit script for CVE-2021-23369, a Remote Code Execution vulnerability in Handlebars template engine versions before 4.7.7. Accepts a target…