
CVE-2022-22965
Spring Framework RCE (CVE-2022-22965) Nmap (NSE) Checker (Non-Intrusive)

Spring Framework RCE (CVE-2022-22965) Nmap (NSE) Checker (Non-Intrusive)

CVE-2024-40725 and CVE-2024-40898, affecting Apache HTTP Server versions 2.4.0 through 2.4.61. These flaws pose significant risks to web servers…

Joomla! < 4.2.8 - Unauthenticated information disclosure

NextSploit is a command-line tool designed to detect and exploit CVE-2025-29927, a security flaw in Next.js

Test CVE-2018-0296 and extract usernames

Exploit code for Jira Mobile Rest Plugin SSRF (CVE-2022-26135)

WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass

A Payload Injector for bugbounties written in go

Safely detect whether a UniFi OS Server is vulnerable to CVE-2026-34908

GitLab 12.9.0 Arbitrary File Read

Exploit for nginx heap buffer overflow (CVE-2026-42533) providing pre-auth RCE via two-pass capture clobbering. Includes info leak, heap spray, and…

dns rebind tool with custom scripts


CVE-2024-3400-RCE

Will attempt to retrieve DB details for FastAdmin instances



Tomcat的文件包含及文件读取漏洞利用POC