
CVE-2025-53770
Network-based vulnerability scanner for detecting systems vulnerable to CVE-2025-53770 (unsafe deserialization). Includes PowerShell and Python…

Network-based vulnerability scanner for detecting systems vulnerable to CVE-2025-53770 (unsafe deserialization). Includes PowerShell and Python…

authz test (CVE-2026-1999 siblings)

CLI scanner that detects whether a target website runs a vulnerable Next.js version affected by CVE-2025-66478 RCE in React Server Components.

Reproduction of a high severty security problem that allows XXE (XML eXternal Entity) attacks on Ktor's XML serialization.

CVE-2025-51458 - DB-GPT Pre-Auth SQL Injection PoC

Shell-based exploit for CVE-2018-11235, a remote code execution vulnerability in Git submodules. Enables testing and validation of the flaw in…

Proof-of-concept exploits for three vulnerabilities in Syncfusion file managers: directory traversal leading to arbitrary file read/write/delete, and…


Exploit code for CVE-2018-6574, a Go language vulnerability allowing arbitrary code execution via crafted import paths.

This Rust PoC exploits CVE-2024-46987, a Path Traversal bug in Camaleon CMS 2.8.0 < 2.8.2 (work on 2.9.0).

Studio 3T v.2025.1.0

Confluence server webwork OGNL injection

Proof-of-concept exploit for CVE-2022-34662 targeting Apache DolphinScheduler, enabling remote code execution via crafted SQL injection in the…

Proof-of-concept exploit for CVE-2022-26884 targeting Apache DolphinScheduler, enabling remote code execution via crafted requests to the workflow…

Proof-of-concept exploit for Apache Struts2 remote code execution vulnerability CVE-2020-17533, leveraging OGNL expression injection for…

CVE-2025-6384: Groovy Sandbox Bypass 2 in CrafterCMS

StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More <= 1.4.0 - Authenticated (Subscriber+)…

一个由AI生成的漏洞验证应用