
Langflow-CVE-2025-3248-Multi-target
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can…

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can…


Apache Struts2框架是一个用于开发Java EE网络应用程序的Web框架。Apache Struts于2020年12月08日披露 S2-061 Struts 远程代码执行漏洞(CVE-2020-17530),在使用某些tag等情况下可能存在OGNL表达式注入漏洞,从而造成远程代码执行,风…

Proof-of-concept exploit for CVE-2018-6574, a remote code execution vulnerability in Go's 'go get' command. Demonstrates exploitation via malicious…

Remote code execution in Mediawiki Score

jquery file upload poc


Remote Code Execution (RCE) vulnerability exists in Sourcecodester Budget and Expense Tracker System 1.0 that allows a remote malicious user to…

C-based detection tool for CVE-2017-2793, enabling identification and analysis of the specific vulnerability in affected systems.

Proof-of-concept exploit for CVE-2025-53964: remote file read/write via malicious XDXF dictionary in GoldenDict 1.5.0/1.5.1, leveraging unsanitized…

Exploit for CVE-2025-3248: injects crafted Python payloads into an unauthenticated API code endpoint to execute arbitrary commands on the target…

a project written in go and java i abandoned for CVE-2021-44228 try to fix it if you can XD

CVE-2022-22947 reproduce

PoC for CVE-2017-0075

Security research repository detailing CVE-2024-46209 (authenticated RCE) and CVE-2024-46210 (stored XSS via file upload) in Redaxo CMS v5.17.1, with…

Demonstration of CVE-2020-0601 aka curveball. Based on the PoC's available at https://github.com/kudelskisecurity/chainoffools and…

CVE-2018-6574

Proof-of-concept for SQL injection in Portabilis i-Educar 2.8.0, demonstrating unauthenticated database access via the getDocuments endpoint with…