Stock vulnerable wordpress RCE poc for wp2shell.
☆104Jul 18, 2026Updated 3 weeks ago
Alternatives and similar repositories for wp2shell-poc
Users that are interested in wp2shell-poc are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Non-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) i…☆54Jul 22, 2026Updated 2 weeks ago
- CVE-2026-63030 + CVE-2026-60137 - “wp2shell”: unauthenticated RCE in WordPress core☆95Jul 18, 2026Updated 3 weeks ago
- wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain☆727Jul 23, 2026Updated 2 weeks ago
- CVE-2025-55182-bypass-waf☆31Jan 8, 2026Updated 7 months ago
- PoC for CVE-2026-3891 — Unauthenticated Arbitrary File Upload leading to Remote Code Execution in Pix for WooCommerce <= 1.5.0☆20Jul 20, 2026Updated 3 weeks ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- JS Enumeration & SAST☆19Updated this week
- DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will auto…☆15Apr 2, 2026Updated 4 months ago
- Bulk scanning tool for ServiceNow CVE-2024-4879 vulnerability☆10Jul 12, 2024Updated 2 years ago
- Go client for Elasticsearch OSINT platform☆15Nov 4, 2023Updated 2 years ago
- Progress Telerik Report Server pre-authenticated RCE chain (CVE-2024-4358/CVE-2024-1800)☆79Jun 6, 2024Updated 2 years ago
- converts sRDI compatible dlls to shellcode☆39Jan 20, 2025Updated last year
- Satanic Crypter A powerful tool designed to convert EXE files into BAT files with advanced features and a modern GUI interface.☆12Jan 4, 2025Updated last year
- CVE-2026-0827 PoC☆19Apr 16, 2026Updated 3 months ago
- "D3MPSEC" is a memory dumping tool designed to extract memory dump from Lsass process using various techniques, including direct system c…☆29Sep 18, 2024Updated last year
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Recon scripts for bug hunting☆10Nov 19, 2021Updated 4 years ago
- Static-Code-Analysis-Helper helps you perform static code analysis.☆33Feb 20, 2026Updated 5 months ago
- CVE-2025-68428 Proof of Concept☆24Jan 8, 2026Updated 7 months ago
- Replay any request as another user to find IDOR/BOLA/BFLA, right in the browser.☆26Jun 16, 2026Updated last month
- ☆22Sep 12, 2025Updated 10 months ago
- Demonstrate how a signed driver can bypass defenses to deploy ransomware on Windows 11 with advanced AV and UAC evasion techniques.☆33Updated this week
- Burp_Suite-Antigravity_AI-Bug_Bounty_Hunter☆64Feb 9, 2026Updated 6 months ago
- A proof-of-concept to demonstrate randomized execution paths and their impact on call stack signatures — ideal for EDR testing, behavior-…☆24Jan 17, 2026Updated 6 months ago
- ☆22Oct 17, 2025Updated 9 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Dumping all keys from a keytab file☆20Dec 1, 2025Updated 8 months ago
- Blog Post: https://blog.doyensec.com/2025/10/08/ksmbd-3.html☆20Oct 8, 2025Updated 10 months ago
- A repo about CTF challenges that I made at several CTF events☆14Mar 20, 2025Updated last year
- A collection of various exploits☆31Sep 17, 2024Updated last year
- JS+ is a browser extension that captures JS URLs from specified domains and scans them with AI.☆22Mar 16, 2026Updated 4 months ago
- Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)☆92Mar 25, 2024Updated 2 years ago
- Detection template for CVE-2025-8110☆22Dec 11, 2025Updated 7 months ago
- Denoising an image is a classical problem that researchers are trying to solve for decades. In earlier times, researchers used filters to…☆12Dec 27, 2022Updated 3 years ago
- Library of Exploiting Last Frame Synchronization (also know as Single Packet Attack) on HTTP/3 - Manipulated version of quic-go lib☆20Jun 23, 2026Updated last month
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Next.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, …☆181May 12, 2026Updated 2 months ago
- dauthi is a tool that takes advantage of API functionality across a variety of MDM solutions to perform user enumeration and single-facto…☆43Apr 23, 2024Updated 2 years ago
- A full-stack web application that aggregates all HackerOne bug bounty programs that have source code repositories (GitHub, GitLab, Bitbuc…☆17Mar 16, 2026Updated 4 months ago
- Direct syscalls Injection to bypass AV/EDR☆10May 18, 2024Updated 2 years ago
- Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fa…☆203Jul 27, 2026Updated 2 weeks ago
- Firebase_Checker is Python tool to analyze APK files and web applications for Firebase-related vulnerabilities. This tool identifies secu…☆58Nov 6, 2025Updated 9 months ago
- Grafana scanner with all public CVEs that I collected in one script to make grafana testing easier☆241Jul 7, 2026Updated last month