This repository contains a proof-of-concept exploit script for CVE-2025-32432, a pre-authentication Remote Code Execution (RCE) vulnerability affecting CraftCMS versions 4.x and 5.x. The vulnerability exists in the asset transform generation feature of CraftCMS.
☆26Apr 27, 2025Updated last year
Alternatives and similar repositories for CVE-2025-32432
Users that are interested in CVE-2025-32432 are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- CraftCMS RCE Checker (CVE-2025-32432)☆10Apr 27, 2025Updated last year
- Nuclei template to detect Apache servers vulnerable to CVE-2024-38473☆30Aug 24, 2024Updated 2 years ago
- POC - CVE-2024–4956 - Nexus Repository Manager 3 Unauthenticated Path Traversal☆16Nov 26, 2024Updated last year
- Widget Options – The #1 WordPress Widget & Block Control Plugin <= 4.0.7 - Authenticated (Contributor+) Remote Code Execution☆13Dec 2, 2024Updated last year
- CVE-2025-68428 Proof of Concept☆24Jan 8, 2026Updated 8 months ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- ☆24Apr 21, 2022Updated 4 years ago
- Wing FTP Server Remote Code Execution (RCE) Exploit (CVE-2025-47812)☆54Jul 14, 2025Updated last year
- ✪ Collection of Metasploit Modules ✪☆17Apr 17, 2026Updated 5 months ago
- This tool serves as an initial version scanner specifically designed for PrestaShop, a popular e-commerce platform. The primary purpose o…☆20Jun 2, 2025Updated last year
- File upload logic flaw in Apache Struts2 exploit☆17Jan 3, 2025Updated last year
- JEB MCP Server for Claude Desktop integration. AI-assisted Android APK reverse engineering with decompilation, batch renaming, cross-refe…☆25Apr 5, 2026Updated 5 months ago
- Smart and efficient tool to automate open redirect detection at scale.☆10Mar 21, 2022Updated 4 years ago
- # 🕵️ PathCatcher v1.0 - Path Traversal & LFI Scanner☆24Jul 13, 2025Updated last year
- POC for CVE-2024-36401. This POC will attempt to establish a reverse shell from the vlun targets.☆35Jul 4, 2024Updated 2 years ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- Confluence Pre-Auth Remote Code Execution via OGNL Injection (CVE-2022-26134)☆44Jun 6, 2022Updated 4 years ago
- CVE-2024-21006 exp☆16Jul 29, 2024Updated 2 years ago
- ☆39Dec 14, 2024Updated last year
- Grep subdomains from web pages.☆42Feb 10, 2025Updated last year
- A critical vulnerability, CVE-2024-53677, has been identified in the popular Apache Struts framework, potentially allowing attackers to e…☆95Dec 20, 2024Updated last year
- ☆14Aug 22, 2025Updated last year
- Wordlists for Wfuzz or Dirbuster☆27Feb 19, 2016Updated 10 years ago
- A Discord Bot to kick users that have specific roles too long.☆10Jun 18, 2020Updated 6 years ago
- A tool for exploiting Kerberos tickets against system with Credential Guard enabled.☆20Sep 2, 2025Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- ☆31Jun 5, 2023Updated 3 years ago
- Two plugins to recover TMP keys from Saleae logic analyser traces☆15Jun 10, 2022Updated 4 years ago
- Authenticated privilege escalation in Camaleon CMS v2.9.0 via improper parameter handling in the updated_ajax endpoint.☆19Feb 4, 2026Updated 7 months ago
- ☆23Nov 27, 2022Updated 3 years ago
- Go based apiban client☆13Jul 17, 2026Updated 2 months ago
- A tiny demo app using SSL pinning to block HTTPS MitM interception☆14Aug 8, 2022Updated 4 years ago
- Handheld WiFi Scanner based on ESP8266☆12Dec 17, 2021Updated 4 years ago
- 基于XOR加密的Shellcode加载器项目,通过内存解密执行实现基础免杀,包含C++加载器和Python加密脚本,可绕过常规静态检测。☆33Jul 24, 2025Updated last year
- PoC. Severity critical.☆74Aug 12, 2024Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Chrome and Firefox extension that lists Amazon S3 Buckets while browsing☆133Mar 30, 2026Updated 5 months ago
- 渗透测试辅助工具箱,反弹shell,命令生成器,输入对应IP端口即可,实现一劳永逸☆37Feb 8, 2023Updated 3 years ago
- ☆73Nov 28, 2025Updated 10 months ago
- CVE-2025-53770 Mass Scanner☆15Jul 29, 2025Updated last year
- AI exploit simulation and continuous security pipeline for LLM apps and AI agents☆16Mar 16, 2026Updated 6 months ago
- DictLoader / 字典匹配ShellCode加载器 / Code By:Tas9er☆15Oct 25, 2025Updated 11 months ago
- CVE-2023-22894☆13Apr 24, 2023Updated 3 years ago