
CVE-2026-65640-
WordPress Core <= 7.0.3 - Authenticated (Author+) Remote Code Execution via Malicious File Upload

WordPress Core <= 7.0.3 - Authenticated (Author+) Remote Code Execution via Malicious File Upload
Python-based exploit for CVE-2014-6271 (Shellshock) targeting vulnerable CGI environments to achieve remote code execution.

Vulnerability Research and Exploit for CVE-2019-10149

Proof-of-concept for a denial-of-service attack via cache poisoning by forcing SPA mode, targeting CVE-2025-43864 in React Router applications.

Proof-of-concept demonstrating CORS to CSRF chain on Sliver's unauthenticated MCP interface, enabling silent interaction with C2 from any webpage.

CVE-2014-7169 Shell Shock

Replicable Blueprint for advanced DDoS Purple Teaming, engineered for the threat landscape. It integrates a Red Elite Teaming offensive…

Exploit for CVE-2014-6271 (Shellshock) targeting Bash environment variable injection to achieve remote code execution on vulnerable systems.

Exploit code for CVE-2014-6271 (Shellshock) targeting vulnerable Bash environments.

CraftCMS has an RCE vulnerability via relational conditionals in the control panel

A lightweight Blind XSS (Cross-Site Scripting) collector and payload server built with Flask

Framework for Man-In-The-Middle attacks

Proof-of-concept exploit chaining CRLF injection in ComfyUI-Manager's config endpoint with an arbitrary git install to achieve unauthenticated remote…

Authenticated Craft CMS RCE PoC for CVE-2026-44011

Docker lab reproducing CVE-2026-100382: unauthenticated argument-injection RCE in MediaWiki ExternalData's #get_program_data, with PoC payloads and…

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…