
CVE-2023-24329-Exploit
Proof-of-concept demonstrating a URL parsing bypass in Python's urllib.parse (CVE-2023-24329) that allows bypassing blocklists by prepending spaces.

Proof-of-concept demonstrating a URL parsing bypass in Python's urllib.parse (CVE-2023-24329) that allows bypassing blocklists by prepending spaces.

Python exploit script for CVE-2022-25581 (ClassCMS 2.4 arbitrary file download) that automates login, CSRF token extraction, malicious zip upload…

Proof-of-concept exploit for CVE-2023-42222 in WebCatalog, demonstrating arbitrary URL execution via Electron's shell.openExternal to bypass security…

Multi-threaded Python PoC scanner for CVE-2023-49103 that checks large URL lists for exposed phpinfo() output with .htaccess bypass via /.css path…

Advisory and PoC for an unauthenticated authorization bypass in Typemill media downloads, using path-equivalent URL variants to access…

CVE-2023-40037: Incomplete Validation of JDBC and JNDI Connection URLs in Apache NiFi

Python-based exploit for CVE-2022-1388, an F5 BIG-IP iControl REST authentication bypass leading to remote code execution. Supports single URL,…

Exploit for CVE-2020-2733 in JD Edwards EnterpriseOne Tools, demonstrating unauthenticated admin password decryption and authentication bypass to…

A PoC for demonstrating CVE-2026-25604

CVE-2022-1388

F5 BIG-IP iControl REST身份验证绕过漏洞

POC for CVE-2026-4444 demonstrating JWT algorithm confusion via untrusted kid injection, including vulnerable Node.js server and Python exploit for…

Powertek PDU身份绕过

Proof-of-concept exploit for CVE-2021-42013, demonstrating path traversal and remote code execution on Apache 2.4.50 via double URL encoding bypass…

Exploit for CVE-2019-17662, a path traversal vulnerability in ThinVNC, demonstrating URL normalization bypass to access arbitrary files on the target…

Exploit for Drupal CVE-2018-7602 remote code execution vulnerability via double URL encoding bypass of sanitize() filter. Includes Docker-based lab…

Proof-of-concept exploit for CVE-2023-41080, demonstrating URL validation bypass in Apache Tomcat to redirect users to arbitrary external sites via…

Analyzes CVE-2025-60423, an authentication bypass in JEECG versions 7.2.8 and 7.2.9, detailing path traversal and URL encoding techniques to bypass…