
CVE-2022-22965-Spring-Core-Rce
批量无损检测CVE-2022-22965

批量无损检测CVE-2022-22965

adaptive agents for dynamic web penetration testing

The Python Version of our Not Go-ing Anywhere Vulnerable Application

A minimalistic LDAP server that is meant for test vulnerability to JNDI+LDAP injection attacks in Java, especially CVE-2021-44228.

Fuzzer for the Sparkplug B IIoT protocol

CVE-2026-53753 — Crawl4AI <0.8.7 unauthenticated RCE (AST sandbox escape via gi_frame.f_back). Lab + PoC, verified e2e.

frida-stalker based system call tracer on windows(x64).


Black-box test whether an LLM chatbot is vulnerable to markdown/HTML exfil (CVE-2025-32711 class). Spins up a sink, sends payloads, renders in…

Detects exposed React Server Components vulnerable to CVE-2025-55182 via RSC negotiation.

Burp Suite extension enhancing Collaborator with context capture, polling history, and optional AES-encrypted authentication for private server…

RCE exploit toolkit for CVE-2025-55182 and CVE-2025-66478 in React Server Components. Includes multiple exploit variants, detection scripts, a…

Traces user inputs to detect injection vulnerabilities in Java methods via JDWP and Frida, identifying potential command and SQL injection points.

PoC for CVE-2026-78997, a Universal XSS in UC Browser for Android. Includes a crafted URL builder, a callback-dispatch oracle, and Frida hooks to…

Exploit for CVE-2020-6514 targeting WebRTC SCTP memory corruption in Android applications. Uses Frida to hook native functions and alter SCTP packets…

Proof-of-concept exploit for CVE-2026-34197, demonstrating authenticated remote code execution in Apache ActiveMQ via Jolokia JMX-HTTP bridge and…

Docker-based reproduction environment for CVE-2021-44228 (Log4Shell) with marshalsec LDAP server, exploit web server, and vulnerable Java application…

Automated exploit for CVE-2022-42889 (Text4Shell) with a vulnerable Dockerized app for testing and manual exploitation guidance.