
CVE-2021-26855
CVE-2021-26855, also known as Proxylogon, is a server-side request forgery (SSRF) vulnerability in Exchange that allows an attacker to send arbitrary…

CVE-2021-26855, also known as Proxylogon, is a server-side request forgery (SSRF) vulnerability in Exchange that allows an attacker to send arbitrary…

Security tool to find potential vulnerable Server Side Request Forgery (SSRF) parameters.

Proof of Concept exploit for Server Side Request Forgery vulnerability in Requests Basket v1.2.1 and before.

CVE-2026-44578 scanner and exploit tool for SSRF in Next.js WebSocket upgrade handler. Detects vulnerable versions, extracts cloud metadata, and…

PoC and internal port brute-forcer for CVE-2023-27163

Valid JQuery that profiles the system and returns info to the server in a fake analytics GET request

SSRF exploit for CVE-2023-27163 in request-baskets, enabling internal port scanning, cloud metadata probing, and service discovery via malicious…

CVE-2026-33340: Critical SSRF in lollms-webui /api/proxy - Unauthenticated arbitrary request forgery (CVSS 9.1)

Analysis via script CVE-2023-5612

PoC and Disclosure for CVE-2023-7231 – Memcached Gopher RCE chain

CVE-2023-25203: Application Vulnerable to SSRF (Server Side Request Forgery) Attacks

Disclosure of a Server-Side Request Forgery (SSRF) vulnerability in Inflectra SpiraTeam 7.2.00, detailing the attack vector, impacts, and vendor…

CVE-2026-33693: SSRF via 0.0.0.0 Bypass in activitypub-federation-rust v4_is_invalid() (CVSS 6.5 Moderate)

An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability

CVE-2022-41040 - Server Side Request Forgery (SSRF) in Microsoft Exchange Server

Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)

[CVE-2021-21975] VMware vRealize Operations Manager API Server Side Request Forgery (SSRF)