
scan4log4j
Python script that sends CVE-2021-44228 log4j payload requests to url list

Python script that sends CVE-2021-44228 log4j payload requests to url list

ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate…



PoC for CVE-2022-46169 - Unauthenticated RCE on Cacti <= 1.2.22

Exploitation Script for CVE-2020-0688 "Microsoft Exchange default MachineKeySection deserialize vulnerability"

A ModSecurity ruleset for detecting potential attacks using CVE-2018-6389

CVE-2021-26855, also known as Proxylogon, is a server-side request forgery (SSRF) vulnerability in Exchange that allows an attacker to send arbitrary…


Proof of concept for arbitrary OS command execution on Guangzhou/V-SOL 1GE ONU devices (CVE-2020-8958)

PoC of HTTP Request Smuggling in nodejs (CVE-2020-8287)

PoC for CVE-2020-8165

Proof-of-concept exploit for CVE-2021-26855 and CVE-2021-27065. Unauthenticated RCE in Exchange.

A short demo of CVE-2021-44228

CVE-2022-39275 Setup and POC

Writeup of a Denial of Service vulnerability in the vBulletin 3.8.7 friends list.

C# implementation of BasuCert/WinboxPoC [Winbox Critical Vulnerability (CVE-2018-14847)]

A CLI tool that exploits vulnerabilities in React Server Components and Server Actions (CVE-2025-55182, CVE-2025-66478) to achieve remote code…