
CVE-2026-23918-Apache-HTTP-Server-DoubleFree-PoC
Proof-of-concept exploit for CVE-2026-23918, a double-free vulnerability in Apache HTTP Server, demonstrating remote crash via crafted requests.

Proof-of-concept exploit for CVE-2026-23918, a double-free vulnerability in Apache HTTP Server, demonstrating remote crash via crafted requests.

Langflow 在对用户提交的“验证代码”做 AST 解析和编译时,在未做鉴权与沙箱限制的情况下调用了 Python 的 compile()/exec()(以及在编译阶段会评估函数默认参数与装饰器),攻击者可把恶意载荷放在参数默认值或装饰器里,借此在服务器上下文中执行任意语句(反弹…

Cisco Catalyst SD-WAN 身份验证绕过漏洞(CVE-2026-20127)利用EXP

Yaws web server OS command injection POC

Yaws web server XML external entity injection POC

Python exploit for CVE-2021-20038 targeting SonicWall SSL VPN with command-line URL/file input for remote code execution.

Exploit for CVE-2021-21972 targeting VMware vCenter with options for webshell or SSH key upload, proxy support, and batch scanning.

批量检测幽灵猫漏洞

MinIO敏感信息泄露漏洞批量扫描poc&exp

Python-based exploit for CVE-2023-4165 targeting Tongda OA, enabling automated vulnerability verification against single or multiple URLs via…

Python exploit for CVE-2023-4166 targeting Tongda OA. Supports single URL and file-based batch scanning for automated vulnerability verification.

harbor(<1.7.6/1.8.3) privilege escalation (CVE-2019-16097)

CVE-2025-1974 PoC 코드

GitLab-Graphql-CVE-2020-26413 POC


Batch vulnerability scanner for CVE-2023-42793 targeting JetBrains TeamCity servers. Automates credential extraction and login URL discovery across…

Proof-of-concept exploit for CVE-2022-31793 with IP/file-based target scanning, validation mode, and arbitrary file read via HTTP requests.

Nortek Control Linear eMerge E3-Series 信息泄露