
POC-CVE-2018-6574
Proof-of-concept exploit for CVE-2018-6574 targeting a Go web server vulnerability. Demonstrates remote code execution via crafted HTTP requests.

Proof-of-concept exploit for CVE-2018-6574 targeting a Go web server vulnerability. Demonstrates remote code execution via crafted HTTP requests.

Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)

Proof-of-concept exploit for CVE-2026-5029, delivering unauthenticated remote code execution via the run-code MCP tool on exposed HTTP endpoints.…

Stored XSS via User-Agent in Admin Order View in PhocaCart

Passive CVE-2025-55182 detection tool for vulnerable React Server Components. Scans package.json, JavaScript bundles, HTTP headers, and API endpoints…

PoC reproducer for CVE-2026-49098 (Apache Camel camel-kafka): the non-Camel-prefixed kafka.OVERRIDE_TOPIC header escapes the upstream HTTP header…

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

Automatically identify deserialisation issues in Java and .NET applications by using active and passive scans

Fuzzing Framework for Modules in Apache HTTPD Server

Security Advisory: HTTP Header Injection via Unvalidated CR and LF in Header Values (tiny_http)

Proof-of-concept reproduction of an nginx heap overflow and info leak (CVE-2026-42533) with two attack surfaces, debug analysis, and a full RCE chain.

Discover input surfaces and security issues in compiled .NET assemblies — without running them.

Proof-of-concept exploit for CVE-2026-34197, demonstrating authenticated remote code execution in Apache ActiveMQ via Jolokia JMX-HTTP bridge and…

Proof-of-concept exploit for CVE-2020-5245, demonstrating expression language injection in Dropwizard REST endpoints via crafted HTTP parameters.

PoC reproducer for CVE-2026-49097 (Apache Camel camel-irc): the non-Camel-prefixed irc.sendTo header escapes the HTTP header filter and overrides the…

Proof-of-concept exploit for CVE-2024-38475 targeting Apache HTTP Server mod_rewrite improper escaping, enabling URL-to-filesystem mapping for code…

Proof-of-concept exploit for CVE-2022-22965 (Spring4Shell) targeting Java Spring Framework applications via crafted HTTP requests.

Proof-of-concept exploit for CVE-2018-6574, a remote code execution vulnerability in Go's net/http package via crafted HTTP requests.