
CVE-2025-29927
PoC | NextJS Middleware 15.2.2 - Authorization Bypass

PoC | NextJS Middleware 15.2.2 - Authorization Bypass
Exploitable target to CVE-2017-5638

CVE-2022-24716 (Arbitrary File Disclosure Icingaweb2)

Documentation of a denial-of-service vulnerability in the Rizin reverse engineering framework's ELF parser, caused by a forged DT_VERNEEDNUM value…

CVE-2024-36401-GeoServer Property 表达式注入 Rce woodpecker-framework 插件

Proof-of-concept demonstrating authorization bypass in Spring Security's RegexRequestMatcher (CVE-2022-22978) using CRLF injection, with analysis and…

Silly Rails App to demonstrate vuln CVE-2013-0156

基于Pocsuite3 框架编写的漏洞验证与利用脚本,用于检测 n8n工作流自动化工具中的认证后远程代码执行漏洞(RCE)

ช่องโหว่ CVE-2023-35674 *สถานะ: ยังไม่เสร็จ*

Log4Shell (CVE-2021-44228) PoC Application

The first proof of concept of the Contao CMS RCE

CVE-2023-45503 Reference

web2py/web2py @ e94946d

PowerShell tool that extracts Active Directory artifacts via LDAP or ADWS and generates Excel reports for auditing, DFIR, and penetration testing.

Python CLI that exploits CVE-2026-48907 in Joomla JCE via profile-import upload, verifies shell paths, and opens an interactive command channel on…

Melody is a transparent internet sensor built for threat intelligence. Supports custom tagging rules and vulnerable application simulation.

GoLismero - The Web Knife

Spring messaging STOMP protocol RCE