Cybersecurity Researcher • Exploit Developer • Vulnerability Research
Public exploits published to Exploit-DB:
| EDB-ID | Target | CVE | Type | Exploit-DB |
|---|---|---|---|---|
| EDB-52645 | Joomla JCE 2.9.15 | CVE-2026-48907 | Unauthenticated RCE | View |
| EDB-52681 | FreePBX 17.0.2 | CVE-2025-57819 | Remote Code Execution | View |
| EDB-52643 | D-Link DNS_340L | CVE-2024-10914 | OS Command Injection / RCE | View |
| EDB-52619 | WordPress Bricks Builder Theme | CVE-2024-25600 | Unauthenticated RCE | View |
Public CVE Exploits Published:
| CVE | Target | Type | Repo |
|---|---|---|---|
| CVE-2026-39987 | Marimo | Pre-Auth RCE | Exploit |
| CVE-2026-9198 | IBM Langflow OSS | Unauthenticated RCE | Exploit |
| CVE-2026-34197 | Apache ActiveMQ / Jolokia | RCE | Exploit |
| CVE-2026-31816 | Budibase | Auth Bypass → RCE | Exploit |
| CVE-2026-48907 | Joomla JCE | Unauthenticated RCE | Exploit |
| CVE-2026-24061 | GNU InetUtils telnetd | Auth Bypass / RCE | Exploit |
| CVE-2026-31431 | Linux Kernel AF_ALG | Local Privilege Escalation | Exploit |
| CVE-2025-57819 | FreePBX | Unauthenticated RCE | Exploit |
| CVE-2025-32463 | Sudo | Local Privilege Escalation | Exploit |
| CVE-2024-10914 | D-Link NAS | RCE / Command Injection | Exploit |
| CVE-2024-27198 | JetBrains TeamCity | Authentication Bypass | Exploit |
| CVE-2024-25600 | WordPress Bricks Builder | RCE | Exploit |
| CVE-2024-4577 | PHP CGI | RCE / Argument Injection | Exploit |
| CVE-2024-3273 | D-Link Devices | RCE / Command Injection | Exploit |
| CVE-2024-1561 | Gradio | Arbitrary File Read / Path Traversal | Exploit |
| CVE-2023-51467 | Apache OFBiz | SSRF / Auth Bypass | Exploit |
| CVE-2023-43208 | Mirth Connect | RCE | Exploit |
| CVE-2023-32315 | Openfire | Authentication Bypass | Exploit |
| CVE-2023-23752 | Joomla | Improper Access Control | Exploit |
| CVE-2022-33891 | Apache Spark | Command Injection / RCE | Exploit |
| CVE-2022-34753 | Schneider Electric SpaceLogic C-Bus | OS Command Injection | Exploit |
| CVE-2022-0543 | Redis | Lua Sandbox Escape / RCE | Exploit |
| CVE-2022-0165 | WordPress KingComposer | Validation Bypass | Exploit |
| CVE-2021-43798 | Grafana | Path Traversal / File Read | Exploit |
| CVE-2021-42013 | Apache HTTP Server | Path Traversal / RCE | Exploit |
| CVE-2021-22205 | GitLab | Unauthenticated RCE | Exploit |
| CVE-2021-29441 | Nacos | Authentication Bypass | Exploit |
| CVE-2021-4191 | GitLab | User Enumeration | Exploit |
| CVE-2021-34621 | WordPress | Privilege Escalation | Exploit |
| CVE-2021-22873 | Revive Adserver | Open Redirect | Exploit |
| CVE-2019-15107 | Webmin | RCE / Command Injection | Exploit |
| CVE-2019-17382 | Zabbix | Authentication Bypass | Exploit |
| CVE-2018-18778 | ACME mini_httpd | Arbitrary File Read | Exploit |
| CVE-2018-14847 | MikroTik RouterOS / WinBox | Path Traversal / File Read | Exploit |
| CVE-2018-10933 | libssh | Authentication Bypass | Exploit |
| CVE-2018-9995 | DVR Systems | Authentication Bypass | Exploit |
| CVE-2017-12615 | Apache Tomcat | RCE / Arbitrary JSP Upload | Exploit |
| CVE-2017-8225 | GoAhead Devices | Information Disclosure | Exploit |
| CVE-2017-7921 | Hikvision Cameras | Authentication Bypass | Exploit |
| CVE-2017-5487 | WordPress | User Enumeration | Exploit |
| CVE-2015-2166 | Ericsson Drutt MSDP | Directory Traversal | Exploit |
| CVE-2015-10141 | Xdebug | Unauthenticated RCE | Exploit |
| CVE-2014-6271 | Bash | Remote Command Execution | Exploit |
| CVE-2012-2122 | MySQL | Authentication Bypass | Exploit |
| CVE-2012-1823 | PHP CGI | RCE / Argument Injection | Exploit |
| CVE-2010-4231 | Camtron / TecVoz IP Cameras | Directory Traversal | Exploit |
| CVE-2008-5862 | webcamXP | Directory Traversal | Exploit |
| Tool | Description | Features | Repo |
|---|---|---|---|
| LiquidNet | IPv4 grabber/scanner for gathering targets globally | Global IPv4 collection, Network scanning, Pentesting support, Ethical hacking framework | Link |
| Webanator | Advanced webcam scraper with cutting-edge algorithms | Real-time extraction, Global coverage, Advanced algorithms, Multi-country support | Link |
| Nuclei Templates | Custom templates for automated vulnerability scanning | Vulnerability detection, Automation, Customizable scans | Link |
| Subdomain Enumeration | Fast Python-based subdomain scanner for reconnaissance | Python-powered, Fast scanning, Reconnaissance, Target enumeration | Link |
| Metasploit Modules | Custom modules for penetration testing | Exploitation, Pentesting, Framework integration | Link |
- Authentication Bypasses — CVE-2017-7921, CVE-2018-9995, CVE-2024-27198
- Remote Code Execution — CVE-2024-4577, CVE-2023-43208, CVE-2020-13945
- Information Disclosure — CVE-2017-5487, CVE-2021-4191
- Access Control Issues — CVE-2023-23752
- Web Framework Exploits — WordPress, Joomla, Apache
- IoT & Hardware — Cameras, Routers, DVR Systems


