
CVE-2026-11112-XXE-via-SVG-Image-Upload
Demonstrates XXE via SVG upload with a vulnerable Flask/lxml parser and an exploit script for arbitrary file read, SSRF, and denial-of-service…

Demonstrates XXE via SVG upload with a vulnerable Flask/lxml parser and an exploit script for arbitrary file read, SSRF, and denial-of-service…

Example Vulnerable .NET HTTP Remoting

Curated collection of injection payloads for web application security testing, covering SSTI, XXE, XSS, SSRF, SQLi, NoSQLi, LDAP, command injection,…

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

通过 jvm 启动参数 以及 jps pid进行拦截非法参数

This project demonstrates a proof-of-concept exploit for CVE-2022-30190, also known as "Follina"—a critical remote code execution vulnerability…

Proof-of-concept exploit for CVE-2021-45026 targeting Rocket Software Zena. Chains stored XSS to remote code execution via REST API task injection on…

Exploit a vulnerable Spring application with the Spring4Shell (CVE-2022-22965) Vulnerability.

PoC exploit for CVE-2019-16759 enabling remote code execution on vBulletin 5.0.0–5.6.2 via malicious POST request due to input validation flaw.

POC for CVE-2021-35448 based on https://www.exploit-db.com/exploits/49601

Exploiting CVE-2021-44228 in Unifi Network Application for remote code execution and more.

Proof of Concept of CVE-2022-30190

This Python proof-of-concept targets a vulnerable MCP (Model Context Protocol) service exposed by the target application. The vulnerability allows an…

CVE-2023-50164 PoC Application & Exploit script

Requests Baskets (CVE-2023-27163) and Mailtrail v0.53

CVE-2023-26039 - ZoneMinder. Any authenticated user can construct an api command to execute any shell command as the web user.

Proof-of-concept exploit for CVE-2022-22965 (Spring4Shell) with a vulnerable Spring Boot application, Python exploit script, and Docker-based lab…

Python-based exploit for CVE-2021-45428, targeting a specific web application vulnerability for penetration testing and security assessment.