
CVE-2025-3248
Exploit scanner detecting unauthenticated code injection in Langflow's /api/v1/validate/code endpoint and executing arbitrary code for authorized…

Exploit scanner detecting unauthenticated code injection in Langflow's /api/v1/validate/code endpoint and executing arbitrary code for authorized…

An explanation and PoC to exploit CVE-2026-25938 Unauthenticated RCE Vulnerability on FUXA

Proof of Concept (PoC) of CVE-2025-69212 related with P7M File Processing

PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB



A portable, padding oracle exploit API

JavaPayload is a collection of pure Java payloads to be used for post-exploitation from pure Java exploits or from common misconfigurations (like not…

infosec enthusiast and madman


Moment.js vuln lab

Liferay XSL - Command Execution (Metasploit)

Freemius Library < 2.2.4 - Subscriber+ Arbitrary Option Update

JSP-less Java Servlets Backdoor inspired by https://www.redteam-pentesting.de/files/redteam-jboss.tar.gz

FastJsonAutoTypeBypass

Exploitation toolkit for RichFaces

A personal collection of Windows CVE I have turned in to exploit source, as well as a collection of payloads I've written to be used in conjunction…