
CVE-2026-11112-XXE-via-SVG-Image-Upload
Demonstrates XXE via SVG upload with a vulnerable Flask/lxml parser and an exploit script for arbitrary file read, SSRF, and denial-of-service…

Demonstrates XXE via SVG upload with a vulnerable Flask/lxml parser and an exploit script for arbitrary file read, SSRF, and denial-of-service…

A POC for the CVE-2025-66516 Apache Tika Vulnerability for educational purposes only

Lightweight PowerShell-based exploit for CVE-2023-3519, enabling remote code execution without external dependencies like NMAP or Python.

CVE-2024-34102 exploit for python3

The `swp_debug` parameter in `admin-post.php` allows remote attackers to include external files containing malicious PHP code, which are evaluated on…

is a PoC script for demonstrating an XML External Entity (XXE) vulnerability exploitation

CVE-2023-2255 Libre Office

Python exploit for Wonder CMS XSS-to-RCE (CVE-2023-41425) that serves malicious scripts locally, enabling remote code execution without external…

This repo describes about cve-2021-29447 and a small script for exploiting automatically

POC exploit for CVE-2025-33053 (external control of file execution path in URL file)

Tool to help exploit XXE vulnerabilities

Cooolis-ms是一个包含了Metasploit Payload Loader、Cobalt Strike External C2 Loader、Reflective DLL injection的代码执行工具,它的定位在于能够在静态查杀上规避一些我们将要执行且含有特征的代码,帮助红队人员更方便快…

A framework for constructing self-spreading binaries