
CVE-2024-24919
Shell script to exploit CVE-2024-24919, enabling path traversal file retrieval from Check Point Security Gateways. Supports single IP and batch…

Shell script to exploit CVE-2024-24919, enabling path traversal file retrieval from Check Point Security Gateways. Supports single IP and batch…

Zyxel 防火墙远程命令注入漏洞(CVE-2022-30525)

批量扫描TomcatAJP漏洞

F5 BIG-IP iControl REST身份验证绕过漏洞

Exploit for CVE-2022-26134 targeting Confluence Server with remote command execution and reverse shell capabilities. Supports batch scanning and…

Powertek PDU身份绕过


Ivanti EPM SQL Injection Remote Code Execution Vulnerability(Optimized version based on h3)

WordPress JSmol2WP Plugin 1.07版本中存在安全漏洞。攻击者可利用该漏洞读取任意文件。

Nortek Control Linear eMerge E3-Series 信息泄露

Langflow 在对用户提交的“验证代码”做 AST 解析和编译时,在未做鉴权与沙箱限制的情况下调用了 Python 的 compile()/exec()(以及在编译阶段会评估函数默认参数与装饰器),攻击者可把恶意载荷放在参数默认值或装饰器里,借此在服务器上下文中执行任意语句(反弹…

CVE-2022-1388

Chamilo CVE-2023-34960 Batch scan/exploit

Metabase 任意文件读取

Exploit for CVE-2020-1938 (Ghostcat) enabling file read and remote command execution on vulnerable Apache Tomcat servers via the AJP connector.

批量检测幽灵猫漏洞

Python exploit for CVE-2022-24716: arbitrary file disclosure in Icinga Web 2 versions <2.8.6, <2.9.6, <2.10. Usage: python3 exploit.py -u <url> -f…

WordPress File Upload插件任意文件读取漏洞(CVE-2024-9047)批量检测脚本