
Review.CVE-2023-5612
Analysis via script CVE-2023-5612

Analysis via script CVE-2023-5612

Technical analysis and detection guidance for CVE-2025-53770, a critical unauthenticated RCE vulnerability in Microsoft SharePoint Server exploited…

Exploring CVE-2021-42013, using Suricata and OpenVAS to gather info

The Shadow Daemon web application firewall server

Generic attack detection rule set for web application firewalls, protecting against OWASP Top Ten and common vulnerabilities with minimal false…

Serverless AITM Simulation Framework for Entra ID and M365

Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.

CVE-2020-27358 and CVE-2020-27359

A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application that allows an attacker to perform unauthorized…

Pre-authentication RCE exploit for CVE-2025-55182 (React2Shell) targeting React Server Components. Features scanning, OAST verification, WAF bypass,…

CTT-PAN-OS-Exploit – CVE-2024-3400 (CVSS 10.0) with Convergent Time Theory enhancement. Uses α = 0.0302011 temporal dispersion, 33-layer phase…

CVE-2026-21876 PoC: WAF charset bypass (Flask, ASP.NET and Spring Boot stands)

Exploits for Typecho CVE-2024-35538, CVE-2024-35539 and CVE-2024-35540

lib/G/functions.php in Chevereto 1.0.0 through 1.1.4 Free, and through 3.13.5 Core, allows an attacker to perform bruteforce attacks without…

Investigation of CVE-2018-11776 vulnerability that allows attackers to remotely execute code and gain control over Apache Struts-based applications.


HTTP Request Smuggling over HTTP/2 Cleartext (h2c)
