
vulnhuntr
Zero shot vulnerability discovery using LLMs

Zero shot vulnerability discovery using LLMs

Automatically identify deserialisation issues in Java and .NET applications by using active and passive scans

Proof-of-concept exploit for CVE-2020-0601 Windows CryptoAPI spoofing vulnerability, demonstrating rogue CA certificate generation using elliptic…

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

Exploit for CVE-2022-22947: remote code execution in Spring Cloud Gateway via crafted requests to the Actuator endpoint. Includes Python script and…

Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)

CVE-2022-25845 (fastjson 1.2.80) exploit for Spring environments with step-by-step PoC, file read, and arbitrary file write via Jackson/commons-io…

Apache Solr Backup/Restore APIs RCE Poc (CVE-2023-50386)

FasterXML/jackson-databind 远程代码执行漏洞

A simple PoC for WordPress RCE (author priviledge), refer to CVE-2019-8942 and CVE-2019-8943.

CVE-2022-41852 Proof of Concept (unofficial)

CVE-2022-33980 Apache Commons Configuration 远程命令执行漏洞

SolarWinds Orion Platform ActionPluginBaseView 反序列化RCE

Apache Log4j 1.2.X存在反序列化远程代码执行漏洞

SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18,…

Static code analysis scanner for WordPress plugins and themes. Detects vulnerabilities like XSS and SQL injection via modular, extensible…

CVE-2022-24086 about Magento RCE

Apache/Alibaba Dubbo <= 2.7.3 PoC Code for CVE-2021-25641 RCE via Deserialization of Untrusted Data; Affects Versions <= 2.7.6 With Different Gadgets