
Spring-Cloud-Gateway-Nacos
Nacos下Spring-Cloud-Gateway CVE-2022-22947利用环境

Nacos下Spring-Cloud-Gateway CVE-2022-22947利用环境

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

API Scraper Agent for Web API's

Burp extension for wordpress security scanning

批量url检测Spring-Cloud-Gateway-CVE-2022-22947

Apisix系列漏洞:未授权漏洞(CVE-2021-45232)、默认秘钥(CVE-2020-13945)批量探测。

Spring Cloud Gateway Actuator API SpEL表达式注入命令执行(CVE-2022-22947)批量检测工具

REST API automation for Burp Suite Community Edition. Drop-in Java extension exposing send/repeat/history endpoints over a local HTTP API.

Dockerized exploit lab and script for CVE-2026-19478, a critical unauthenticated GitLab GraphQL code injection enabling arbitrary Ruby method calls,…

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

PoC: changedetection.io unauthenticated OpenAPI schema disclosure (CVE-2026-71203, Medium 5.3)

Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

CVE-2023-42442 JumpServer Session 录像任意下载漏洞

PoC exploit for CVE-2022-22947: SpEL injection in Spring Cloud Gateway enabling remote command execution via crafted Actuator API routes.


CVE-2024-26026: BIG-IP Next Central Manager API UNAUTHENTICATED SQL INJECTION

Demonstrates a critical GraphQL batching alias-confusion SQL injection (CVE-2026-5432) with a vulnerable Node.js server and Python exploit for…