
CVE-2022-30525
Zyxel 防火墙远程命令注入漏洞(CVE-2022-30525)

Zyxel 防火墙远程命令注入漏洞(CVE-2022-30525)

Exploit for CVE-2022-26134 targeting Confluence Server with remote command execution and reverse shell capabilities. Supports batch scanning and…


Langflow 在对用户提交的“验证代码”做 AST 解析和编译时,在未做鉴权与沙箱限制的情况下调用了 Python 的 compile()/exec()(以及在编译阶段会评估函数默认参数与装饰器),攻击者可把恶意载荷放在参数默认值或装饰器里,借此在服务器上下文中执行任意语句(反弹…

CVE-2022-1388

Chamilo CVE-2023-34960 Batch scan/exploit

Batch scanner and exploit for CVE-2019-12725, a ZeroShell command injection vulnerability. Supports single URL testing, mass scanning, and…

Python-based exploit for Struts2 S2-061 (CVE-2020-17530) remote command execution vulnerability. Supports single URL, file-based scanning, proxy, and…

PoC exploit for CVE-2021-46422, an OS command injection vulnerability in Korean wireless routers. Includes a Python script for single or batch URL…

CVE-2022-1388-PocExp,新增了多线程,F5 BIG-IP RCE exploitation

A client and chat program for njrat 0.6.4, 0.7d, and 0.7d golden edition.

Spring Cloud Gateway Actuator API SpEL Code Injection (CVE-2022-22947)

Python exploit for CVE-2021-20038 targeting SonicWall SSL VPN with command-line URL/file input for remote code execution.

Python exploit for CVE-2022-3218 that generates a reverse TCP payload via msfvenom and delivers it over HTTP to a target Windows host.

SDT-CW3B1韩国的无线路由器 os cmd 注入PoC