
CVE-2024-4577
Proof-of-concept exploit for CVE-2024-4577, a PHP CGI argument injection vulnerability enabling remote code execution via crafted HTTP requests.

Proof-of-concept exploit for CVE-2024-4577, a PHP CGI argument injection vulnerability enabling remote code execution via crafted HTTP requests.

Proof-of-concept exploit for CVE-2018-6574 targeting a Go web server vulnerability. Demonstrates remote code execution via crafted HTTP requests.

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can…

Proof-of-concept exploit for CVE-2018-6574, a remote code execution vulnerability in Go's net/http package via crafted HTTP requests.

Proof-of-concept exploit for CVE-2020-5245, demonstrating expression language injection in Dropwizard REST endpoints via crafted HTTP parameters.

Proof-of-concept exploit for CVE-2018-6574, a remote code execution vulnerability in Go's net/http package. Demonstrates exploitation of improper…

Automatically identify deserialisation issues in Java and .NET applications by using active and passive scans

Discover input surfaces and security issues in compiled .NET assemblies — without running them.

Fuzzing Framework for Modules in Apache HTTPD Server

Stored XSS via User-Agent in Admin Order View in PhocaCart

CVE-2017-12615 - Apache Tomcat Remote Code Execution (RCE)

Security Advisory: Unchecked Room Lookup Leads to Server Crash (Let's Chat)

Proof-of-concept exploit for CVE-2026-34197, demonstrating authenticated remote code execution in Apache ActiveMQ via Jolokia JMX-HTTP bridge and…

Proof-of-concept reproduction of an nginx heap overflow and info leak (CVE-2026-42533) with two attack surfaces, debug analysis, and a full RCE chain.

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.