
CVE-2017-12149
Interactive exploit for CVE-2017-12149 that executes commands on vulnerable JBoss servers, supporting both Linux and Windows targets with a simple…

Interactive exploit for CVE-2017-12149 that executes commands on vulnerable JBoss servers, supporting both Linux and Windows targets with a simple…

Time-based blind SQL injection exploit for CMS Made Simple <= 2.2.9 (CVE-2019-9053) that extracts username, email, password hash, and salt, with…

Python exploit for CVE-2024-10924 that bypasses Two-Factor Authentication in the Really Simple SSL WordPress plugin, enabling unauthorized…

Proof-of-concept exploit for CVE-2024-10924, an authentication bypass vulnerability in the Really Simple Security WordPress plugin, enabling MFA…

Simple PoC of wpstorecart before 2.5.30 plugin exploit (CVE-2012-3576) written in bash.

CVE-2023-44061 - Simple and Nice Shopping Cart Script V1.0

Simple payload builder

A simple python shell-like exploit for the Shellschok CVE-2014-6271 bug.

Proof-of-concept exploit for CVE-2022-3546, a stored XSS vulnerability in SourceCodester Simple Cold Storage Management System 1.0 via the Create…

Minimal Next.js 12.2 application containerized with Docker, providing a simple Hello World web app and local development instructions.

PoC exploit code for CVE-2021-26855

Authenticated remote code execution exploit for PlaySMS 1.4 via CSV phonebook upload. Provides single-command and interactive shell modes for…

Proof-of-concept exploit for unauthenticated remote code execution in Tatsu Builder WordPress plugin (CVE-2021-25094). Supports multiple shell…

CutePHP Cute News 2.1.2 RCE PoC

Python PoC exploiting CVE-2025-27636, an Apache Camel header injection RCE, supporting command execution, file reads, and reverse shell payloads.

Proof-of-concept implementation for CVE-2026-33017, demonstrating the vulnerability for authorized security testing and research.

Demonstrates CVE-2026-31431 by poisoning the cache for a target file with attacker-controlled payload bytes, illustrating a web cache poisoning…

CVE-2019-12836