
dllspy
Discover input surfaces and security issues in compiled .NET assemblies — without running them.

Discover input surfaces and security issues in compiled .NET assemblies — without running them.

Unauthenticated Remote Code Execution via unsafe deserialization in Microsoft SharePoint Server (CVE-2025-53770)

CVE-2020-10199、CVE-2020-10204漏洞一键检测工具,图形化界面。CVE-2020-10199 and CVE-2020-10204 Vul Tool with GUI.

PoC for CVE-2026-3891 — Unauthenticated Arbitrary File Upload leading to Remote Code Execution in Pix for WooCommerce <= 1.5.0

Vimana is an experimental security tool that aims to provide resources for auditing Python web applications.

Apache ShardingSphere UI YAML解析远程代码执行漏洞

Spring-Kafka-Deserialization-Remote-Code-Execution

Authenticated remote code execution exploit for Jenkins Git Client Plugin 2.8.2 via Jackson deserialization vulnerability (CVE-2019-10392).

Exploit script for CVE-2021-22204, an ExifTool RCE via malicious DjVu files, with manual exploitation steps and reverse shell payloads.

CVE-2024-4879 - Jelly Template Injection Vulnerability in ServiceNow

Proof-of-concept exploit module for CVE-2019-11043 (PHP-FPM remote code execution) with batch scanning capabilities for vulnerable Nginx…

CVE-2020-9547:FasterXML/jackson-databind 远程代码执行漏洞

Case for CVE-2022-30778

PoC for CVE-2022-23940

This includes CVE-2022-22963, a Spring SpEL / Expression Resource Access Vulnerability, as well as CVE-2022-22965, the spring-webmvc/spring-webflux…

PoC for CVE-2020-0601 - CryptoAPI exploit

CVE-2022-32119 - Arox-Unrestricted-File-Upload

CVE-2020-26259: XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has…