
Nagios-CVE-2019-15949-RCE
a PoC for the Nagios CVE-2019-15949 rce in python

a PoC for the Nagios CVE-2019-15949 rce in python

CVE-2024-49375、CVE-2021-42556、CVE-2021-41127

Modular exploit framework targeting CVE-2026-23550 in WordPress, featuring mass exploitation, obfuscation, post-exploitation, and Docker-based C2…

A x86_64 ASM implementation of PinTheft (CVE-2026-43494)

Exploit for PyInstaller CVE-2019-16784

LocalPotato NTLM reflection exploit (CVE-2023-21746) as a Cobalt Strike Beacon Object File

DLL hijacking to rev shell

Exploit for CVE-2024-6232 - Python Tarfile Realpath Overflow

i tried this in Conversor HTB machine

JBoss Autopwn as featured at BlackHat Europe 2010 - this version incorporates CVE-2010-0738 the JBoss authentication bypass VERB manipulation…

Serv-U-FTP CVE-2021-35211 exploit

Exploit CVE-2025-1974 with a single file.

PoC Authentication Bypass to RCE to Exploit CVE-2025-31161

Proof-of-concept exploit for CVE-2024-48990 demonstrating PYTHONPATH hijacking in needrestart to achieve local privilege escalation via SUID binary…

Automated JBoss exploitation script deploying JSP shells with bind/reverse shell, Meterpreter, and VNC support for penetration testing.

Exploit for CVE-2021-4034, a local privilege escalation in polkit's pkexec, providing a root shell via a shared library and GCONV path manipulation.

CheckMK Agent Local Privilege Escalation (PoC)

Exploit for CVE-2020-1472 (Zerologon) that resets the domain controller account password, enabling DCSync, with restoration steps to revert changes.