
CVE-2024-50379-PoC
Batch detection script for Apache Tomcat CVE-2024-50379 race condition remote code execution vulnerability. Supports single and mass scanning via…

Batch detection script for Apache Tomcat CVE-2024-50379 race condition remote code execution vulnerability. Supports single and mass scanning via…

PoC for CVE-2021-43557

Proof-of-concept exploit for CVE-2022-31793 with IP/file-based target scanning, validation mode, and arbitrary file read via HTTP requests.

Ivanti EPM SQL Injection Remote Code Execution Vulnerability(Optimized version based on h3)

Extract payload URLs from Follina (CVE-2022-30190) docx and rtf files

Exploit for CVE-2009-2265 targeting ColdFusion 8.0.1 with JSP reverse shell payload generation and automated upload.

Exploit for CVE-2020-1938 (Ghostcat) enabling file read and remote command execution on vulnerable Apache Tomcat servers via the AJP connector.

CVE-2024-0012批量检测脚本

Langflow 在对用户提交的“验证代码”做 AST 解析和编译时,在未做鉴权与沙箱限制的情况下调用了 Python 的 compile()/exec()(以及在编译阶段会评估函数默认参数与装饰器),攻击者可把恶意载荷放在参数默认值或装饰器里,借此在服务器上下文中执行任意语句(反弹…

CVE-2025-1974 PoC 코드

批量扫描TomcatAJP漏洞

CVE-2022-1388

Tomcat的文件包含及文件读取漏洞利用POC

Zyxel 防火墙远程命令注入漏洞(CVE-2022-30525)

F5 BIG-IP iControl REST身份验证绕过漏洞

WordPress File Upload插件任意文件读取漏洞(CVE-2024-9047)批量检测脚本

D-Link DCS系列账号密码信息泄露漏洞,通过脚本获取账号密码,可批量。

Yaws web server OS command injection POC