
freddy
Automatically identify deserialisation issues in Java and .NET applications by using active and passive scans

Automatically identify deserialisation issues in Java and .NET applications by using active and passive scans

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

CVE-2022-22947

CVE-2022-25845(fastjson1.2.80) exploit in Spring Env!

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)

FasterXML/jackson-databind 远程代码执行漏洞

CVE-2022-41852 Proof of Concept (unofficial)

Apache Log4j 1.2.X存在反序列化远程代码执行漏洞

Exploit for Jenkins serialization vulnerability - CVE-2016-0792

SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18,…

Apache Solr Backup/Restore APIs RCE Poc (CVE-2023-50386)

Apache/Alibaba Dubbo <= 2.7.3 PoC Code for CVE-2021-25641 RCE via Deserialization of Untrusted Data; Affects Versions <= 2.7.6 With Different Gadgets

CVE-2022-33980 Apache Commons Configuration 远程命令执行漏洞

SolarWinds Orion Platform ActionPluginBaseView 反序列化RCE

Unauthenticated Remote Code Execution via unsafe deserialization in Microsoft SharePoint Server (CVE-2025-53770)

h2-jdbc(https://github.com/h2database/h2database/issues/3195) & mysql-jdbc(CVE-2021-2471) SQLXML XXE vulnerability reproduction.

CVE-2022-24086 about Magento RCE