
Spring-Cloud-Gateway-Nacos
Nacos下Spring-Cloud-Gateway CVE-2022-22947利用环境

Nacos下Spring-Cloud-Gateway CVE-2022-22947利用环境

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

Burp extension for wordpress security scanning

CVE-2026-34910/34909 — UniFi OS unauth RCE + file read via ..%2f auth bypass (CVSS 10.0, KEV, Mirai ITW)

Apisix系列漏洞:未授权漏洞(CVE-2021-45232)、默认秘钥(CVE-2020-13945)批量探测。

CVE-2018-25031 tests

Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

Spring Cloud Gateway Actuator API SpEL表达式注入命令执行(CVE-2022-22947)批量检测工具

批量url检测Spring-Cloud-Gateway-CVE-2022-22947

A PoC exploit for CVE-2021-4191 - GitLab User Enumeration.

Proof-of-concept exploit for CVE-2026-68929, demonstrating unauthenticated cross-tenant takeover of FastGPT WeChat channels via public shareId,…

Standalone authorized universal HTTP PoC for CVE-2026-75157

Reproducible BOLA/IDOR PoC against Onlook's tRPC API (CVE-2026-65013), with a 12-step exploit chain, vulnerable and patched Docker targets, and…

GLPI Privilege Escalation via authtype Manipulation PoC - CVE-2026-53625. Ethical PoC for the GLPI vulnerability allowing a Technician to take full…

CVE-2023-42442 JumpServer Session 录像任意下载漏洞

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

PoC exploit for CVE-2022-22947: SpEL injection in Spring Cloud Gateway enabling remote command execution via crafted Actuator API routes.