
CVE-2017-8570
Python-based exploit for CVE-2017-8570, generating malicious RTF files with embedded SCT and EXE payloads for targeted exploitation.

Python-based exploit for CVE-2017-8570, generating malicious RTF files with embedded SCT and EXE payloads for targeted exploitation.

Code sample for using exploit CVE-2019-5736 to mine bitcoin with no association to original container or user.

Detailed disclosure of CVE-2024-34831: Stored XSS in GibbonEdu Core v26.0.00 leading to privilege escalation via crafted imageLink parameter and…

Proof-of-concept exploit for a heap overflow vulnerability in ResHacker.exe, generating a malicious payload file to trigger the overflow and…

Proof-of-concept exploit for CVE-2019-1221 targeting Internet Explorer 11 32-bit on Windows 10 x64 up to RS5, using VBScript.Encode and CVE-2019-0768…

Proof of concept code in C# to exploit the WinRAR ACE file extraction path (CVE-2018-20250).

Proof of Concept for Path Traversal in Apache Struts ("CVE-2023-50164")

Python-based proof-of-concept exploit for CVE-2017-9791 (Apache Struts2 S2-048) with check and command execution modes for penetration testing.

double-free bug in WhatsApp exploit poc

Python PoC exploit for CVE-2015-3306 ProFTPD directory traversal. Copies files and drops a PHP backdoor into webroot for remote command execution via…

Exploit script for CVE-2024-50379, automating JSP webshell upload and execution via a race condition in Apache Tomcat.

Go-based proof-of-concept exploit for CVE-2020-11546, targeting a remote code execution vulnerability in SuperWebMailer 5.50. Provides a ready-to-use…

Multi-language PoC exploit collection for CVE-2021-4034 (polkit pkexec local privilege escalation), including C, Python2, and Python3 implementations…

Python exploit script for CVE-2017-10271 targeting Oracle WebLogic Server WLS-WSAT component. Supports command execution with output and direct JSP…

C# PoC exploit for CVE-2023-23397 that sends malicious Outlook meeting invites with a UNC path trigger for NTLM credential theft.

CLI tool to detect and exploit CVE-2025-3248, a critical RCE vulnerability in Langflow, with customizable payload execution for authorized…

repo showcasing generating "psychic signatures for java" implemented in a nodejs environment 😅

Generates reverse shell payloads targeting the GitLab-shell vulnerability CVE-2024-32002 for exploitation testing.