
Solr-GRAB
Steal Apache Solr instance Queries with or without a username and password.

Steal Apache Solr instance Queries with or without a username and password.

Apache Solr instances that may be affected by CVE-2026-44825, related to Velocity Template Remote Code Execution (RCE) conditions.

Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API…

RCE on Apache Solr using deserialization of untrusted data via jmx.serviceUrl

Apache Solr DataImport Handler RCE

Apache Solr RCE (ENABLE_REMOTE_JMX_OPTS="true")

Apache Solr RCE via Velocity template

Apache Solr SSRF(CVE-2021-27905)

Apache Solr Backup/Restore APIs RCE Poc (CVE-2023-50386)

Exploit for Apache Solr remote code execution via Velocity template injection, enabling command execution on vulnerable instances through crafted…

Proof-of-concept exploit for CVE-2019-0193, a remote code execution vulnerability in Apache Solr, enabling authenticated attackers to execute…

☄️ Mass reconnaissance & exploitation framework for Apache Solr CVE-2026-44825 — Velocity template injection to RCE

Apache Solr remote code execution via dataImportHandler

[CVE-2021-27905] Apache Solr ReplicationHandler Server Side Request Forgery (SSRF)

A Nuclei template for Apache Solr affected by Apache Log4J CVE-2021-44228

CTF write-up documenting CVE-2019-17558 exploitation in Apache Solr, covering reconnaissance, Metasploit limitations, manual Velocity template…

Apache Solr Poc CVE-2017-3164 CVE-2017-12629

Proof-of-concept exploit for CVE-2024-45216 targeting Apache Solr instances via HTTP. Executes remote code execution against vulnerable hosts.