
cve-2022-42889-intercept
通过 jvm 启动参数 以及 jps pid进行拦截非法参数

通过 jvm 启动参数 以及 jps pid进行拦截非法参数

Manual exploit for CVE-2020-9496, an unauthenticated Java deserialization RCE in Apache OFBiz XML-RPC, with step-by-step instructions for payload…

POC Highlighting Obfuscation Techniques used by FIN threat actors based on cmd.exe's replace functionality and cmd.exe/powershell.exe's stdin command…

Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.

Simple exploit for Wing FTP Server RCE (CVE-2025-47812) to run commands and get a reverse shell. For educational use only.

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address

Unauthenticated remote code execution exploit for Wing FTP Server < 7.4.4, enabling command execution and reverse shells via Lua injection in session…

Unauthenticated remote code execution exploit for Wing FTP Server (CVE-2025-47812) with multiple reverse shell payloads, interactive and CLI modes,…

Python PoC for CVE-2025-47812, unauthenticated RCE in Wing FTP Server <= 7.4.3 via NULL-byte Lua injection into session files

Framework for Digiduck Development Boards running ATTiny85 processors and micronucleus bootloader!

CVE-2021-43287 CVE-2021-43288 CVE-2021-43289 CVE-2021-43290

Docker-based educational lab demonstrating Log4Shell (CVE-2021-44228) RCE exploitation with a vulnerable Java application, LDAP redirector, and…

PoC exploit for CVE-2021-33026 that poisons Redis cache in Flask-Cache to achieve remote code execution via malicious pickle deserialization.

Java-based proof-of-concept exploit for CVE-2021-44228 (Log4Shell) enabling remote command execution, OS information gathering, and arbitrary…