
cve-2025-3248
Langflow 在对用户提交的“验证代码”做 AST 解析和编译时,在未做鉴权与沙箱限制的情况下调用了 Python 的 compile()/exec()(以及在编译阶段会评估函数默认参数与装饰器),攻击者可把恶意载荷放在参数默认值或装饰器里,借此在服务器上下文中执行任意语句(反弹…

Langflow 在对用户提交的“验证代码”做 AST 解析和编译时,在未做鉴权与沙箱限制的情况下调用了 Python 的 compile()/exec()(以及在编译阶段会评估函数默认参数与装饰器),攻击者可把恶意载荷放在参数默认值或装饰器里,借此在服务器上下文中执行任意语句(反弹…

Escaner de identificacion de vulnerabilidades para CVE-2025-4322

CVE-2026-8181: Burst Statistics Auth Bypass → REST API takeover & admin creation. Python 2.7. Educational use only.

Python exploit for CVE-2025-6254 targeting unauthenticated privilege escalation in Doctreat Core <= 1.6.8. Supports single URL and multi-target…

Mass Scanner for CVE-2022-29455 on Elementor Plugins Wordpress

Exploit script for CVE-2024-25600, a remote code execution vulnerability in WordPress Bricks Builder, with multi-POC support and configurable threads.

Wordpress likes and dislikes add-on - SQL Injection

Multi-threaded exploit script for CVE-2024-24919 that scans a list of IP addresses and outputs results, intended for educational use.