
CVE-2019-12086
jackson unserialize

jackson unserialize

Python exploit for CVE-2025-6254 targeting unauthenticated privilege escalation in Doctreat Core <= 1.6.8. Supports single URL and multi-target…

Proof-of-concept exploit for CVE-2013-4660 demonstrating YAML deserialization remote code execution in a Dockerized Node.js environment with…

Proof-of-concept exploit for CVE-2026-23918, a double-free vulnerability in Apache HTTP Server, demonstrating remote crash via crafted requests.

Proof-of-concept exploit for CVE-2024-22120 that leverages time-based SQL injection and gopher-based SSRF to achieve remote code execution on…

Python script to verify Apache Tomcat CVE-2020-1938 vulnerability by sending crafted requests to the AJP port, allowing file read and potential code…

Cisco Catalyst SD-WAN 身份验证绕过漏洞(CVE-2026-20127)利用EXP

Batch vulnerability scanner for CVE-2023-42793 targeting JetBrains TeamCity servers. Automates credential extraction and login URL discovery across…

Langflow 在对用户提交的“验证代码”做 AST 解析和编译时,在未做鉴权与沙箱限制的情况下调用了 Python 的 compile()/exec()(以及在编译阶段会评估函数默认参数与装饰器),攻击者可把恶意载荷放在参数默认值或装饰器里,借此在服务器上下文中执行任意语句(反弹…

Exploit for CVE-2009-2265 targeting ColdFusion 8.0.1 with JSP reverse shell payload generation and automated upload.

CVE-2024-0012批量检测脚本

Batch detection script for Apache Tomcat CVE-2024-50379 race condition remote code execution vulnerability. Supports single and mass scanning via…

WordPress File Upload插件任意文件读取漏洞(CVE-2024-9047)批量检测脚本

Cleo 远程代码执行漏洞批量检测脚本(CVE-2024-50623)

Python-based proof-of-concept exploit for CVE-2025-29927, a Next.js privilege bypass vulnerability. Supports single-target and batch scanning with…

Multi-threaded Python scanner for CVE-2025-30208 Vite path traversal vulnerability with custom payload support, batch scanning, and proxy debugging.

CVE-2025-1974 PoC 코드

Exploit for CVE-2025-26319 targeting Flowise's /api/v1/attachments endpoint, enabling unauthenticated arbitrary file upload and webshell generation…