
CVE-2025-49844_POC
Proof-of-concept exploit for CVE-2025-49844, a Redis Lua script remote code execution vulnerability, demonstrating exploitation and providing…

Proof-of-concept exploit for CVE-2025-49844, a Redis Lua script remote code execution vulnerability, demonstrating exploitation and providing…

CVE-2020-26217 XStream反序列化的poc

An Python Exp For "GeoServer"

NodeJS-based exploit script and scanner for the React Server Components "React2Shell" vulnerability (CVE-2025-55182).

Unauthenticated remote code execution proof-of-concept for CVE-2026-23744 targeting MCPJam Inspector. Generates crafted MCP serverConfig payloads to…

Proof-of-concept exploit for CVE-2021-22204, a remote code execution vulnerability in ExifTool, demonstrating exploitation via crafted image files.

Python exploit for CVE-2021-32849, a command injection in Gerapy, enabling remote code execution with reverse shell.

Go-based exploit for CVE-2022-40684 targeting Fortinet FortiGate devices. Automates authentication bypass to gain administrative access via the web…

Exploit tool for CVE-2019-11043, targeting insecure pointer arithmetic in PHP-FPM to gain remote access on poorly configured PHP servers via…


Exploit and mass-check script for CVE-2022-1388 targeting F5 BIG-IP iControl REST unauthenticated remote command execution. Supports single host,…

Struts2 RCE CVE-2017-5638 CLI shell

Proof-of-concept exploit for CVE-2023-39362, an authenticated command injection in Cacti's SNMP options. Includes a vulnerable Docker environment for…

Unverified Password Change (CWE-620)


Proof-of-concept exploit for a command injection vulnerability in VitalPBX Task Manager module, demonstrating reverse shell payload delivery via cron…

CVE-2019-3396 Memshell for Behinder

CVE-2021-46704 GenieACS Command Injection POC