
Langflow-CVE-2025-3248-Multi-target
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can…

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can…

Proof-of-concept exploit for CVE-2022-34919, demonstrating unauthenticated arbitrary file upload and RCE in Contensis CMS Classic interface via…

Python exploit for CVE-2022-46169, a remote code execution vulnerability in Cacti v1.2.22. Enables authenticated RCE via crafted HTTP requests for…

Proof-of-concept exploit for Apache HTTP Server 2.4.49/2.4.50 path traversal vulnerability (CVE-2021-41773) enabling remote code execution via CGI…

Proof-of-concept exploit for CVE-2025-22604, a remote code execution vulnerability in Cacti network monitoring software. Enables authenticated RCE…

Python exploit for CVE-2011-3192 (Apache Range Header Denial of Service). Executes multi-threaded HTTP requests to exhaust server resources. Requires…

Exploit scripts for Apache HTTP Server 2.4.49 directory traversal vulnerability (CVE-2021-41773), enabling path traversal and potential RCE via…

DoS tool for HTTP requests (inspired by hulk but has more functionalities)

Proof-of-concept exploit for CVE-2026-0768 in Langflow, allowing remote command execution via crafted HTTP requests.

Proof-of-concept exploit for CVE-2026-5027 in Langflow, enabling remote command execution via crafted HTTP requests.

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2,…

Proof-of-concept exploit for CVE-2021-41773, an Apache HTTP Server 2.4.49 path traversal vulnerability enabling remote file disclosure and CGI…

In the realm of cybersecurity, accurately identifying and characterizing web servers is crucial for threat detection, vulnerability assessment, and…

The successor to reDuh, pwn a bastion webserver and create SOCKS proxies through the DMZ. Pivot and pwn.

A DNS rebinding attack framework.

A curated collection of top-tier penetration testing tools and productivity utilities across multiple domains. Join us to explore, contribute, and…

TCP tunneling over HTTP/HTTPS for web application servers

Generates randomized, lint-validated C2 malleable profiles for Cobalt Strike, automating HTTP/S, DNS, SMB, and SSH beacon configuration with…