


Spring4Shell , Spring Framework RCE (CVE-2022-22965) , Burpsuite Plugin

POC CVE-2024-46982

CVE-2024-26026: BIG-IP Next Central Manager API UNAUTHENTICATED SQL INJECTION

CVE-2025-41090 (brokeCLAUDIA): Broken access control in microCLAUDIA, the anti-ransomware platform by CCN-CERT.

Apache Text4Shell (CVE-2022-42889) Burp Bounty Profile


CVE-2026-27944 - Nginx UI Unauthenticated Backup Download & Decryption

Minimal Python proof-of-concept for CVE-2026-64638 that sends a crafted HTML/JSONP XSS payload to WordPress wp-login.php.

PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)

R/W



Reproduce CVE-2023-2033

Strapi CVE-2026-27886. Leaking sensitive data via relational filtering due to lack of query sanitization

Code to reproduce the vulnerability individually

The code for personally reproducing the corresponding vulnerability