
CVE-2026-37197
Proof-of-concept for CVE-2026-37197: Server-Side Request Forgery (SSRF) in NukeViet CMS v4.5.07 admin remote upload, enabling internal network…

Proof-of-concept for CVE-2026-37197: Server-Side Request Forgery (SSRF) in NukeViet CMS v4.5.07 admin remote upload, enabling internal network…

CVE-2026-44578

CVE-2026-44578 scanner and exploit tool for SSRF in Next.js WebSocket upgrade handler. Detects vulnerable versions, extracts cloud metadata, and…

SSRF exploit for CVE-2023-27163 in request-baskets, enabling internal port scanning, cloud metadata probing, and service discovery via malicious…

CVE-2026-33693: SSRF via 0.0.0.0 Bypass in activitypub-federation-rust v4_is_invalid() (CVSS 6.5 Moderate)

Unauthenticated SSRF in Chamilo LMS via PENS plugin (pens.php) — CVSS 7.5

CVE-2026-33340: Critical SSRF in lollms-webui /api/proxy - Unauthenticated arbitrary request forgery (CVSS 9.1)

Security tool to find potential vulnerable Server Side Request Forgery (SSRF) parameters.

Local File Inclusion via Server Side Request Forgery

Apache Solr < 8.8.2 Server Side Request Forgery

Proof of concept demonstrating Server-Side Request Forgery in ChatGPT, allowing attackers to force the AI to make arbitrary HTTP requests, exposing…

Unauthenticated SSRF PoC in WordPress Fusion Builder <3.6.2 (CVE-2022-1386)

PoC and internal port brute-forcer for CVE-2023-27163

Analysis via script CVE-2023-5612

Proof of Concept exploit for Server Side Request Forgery vulnerability in Requests Basket v1.2.1 and before.

PoC and Disclosure for CVE-2023-7231 – Memcached Gopher RCE chain

Disclosure of a Server-Side Request Forgery (SSRF) vulnerability in Inflectra SpiraTeam 7.2.00, detailing the attack vector, impacts, and vendor…

Hurrakify <= 2.4 - Unauthenticated Server-Side Request Forgery