
CVE-2026-21003-JWT-none-Algorithm-Bypass-via-kid-Header-Omission
Proof-of-concept exploit for CVE-2026-21003 demonstrating JWT authentication bypass by omitting the kid header and using the 'none' algorithm to…

Proof-of-concept exploit for CVE-2026-21003 demonstrating JWT authentication bypass by omitting the kid header and using the 'none' algorithm to…

Multi-domain HTTP 403 bypass scanner that tests header manipulation techniques to discover hidden access paths on web servers, supporting bulk domain…

Proof-of-concept exploit for Apache Struts2 S2-045 (CVE-2017-5638) remote code execution vulnerability via malicious Content-Type header.

Python PoC exploiting CVE-2025-27636, an Apache Camel header injection RCE, supporting command execution, file reads, and reverse shell payloads.

Reproducer for CVE-2026-33454: Apache Camel camel-mail header injection to RCE via camel-exec

A PoC Exploit for CVE-2024-3105 - The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress Remote Code Execution (RCE)

CVE-2026-73034 — DB-GPT v0.8.1 unauth path traversal → arbitrary file write as root via user-id header. Verified + fix diff

Exploit tool that transforms SMTP header injection into remote code execution with self-propagating worm capabilities, featuring persistence…

PoC for CVE-2025-25257, a critical unauthenticated SQL injection in FortiWeb. Exploits SQLi via the Authorization header to write a webshell and gain…

Exploit for CVE-2024-4040 – Authentication bypass in CrushFTP via CrushAuth cookie and AWS-style header spoofing. Stealthy Python PoC with secure…

Python proof-of-concept exploit for Apache Struts2 RCE vulnerability CVE-2017-5638, demonstrating remote code execution via crafted Content-Type…

Proof-of-concept exploit for Apache Struts2 remote code execution vulnerability CVE-2017-5638, demonstrating exploitation via crafted Content-Type…

Exploit for Apache Struts2 remote code execution vulnerability (CVE-2017-5638) via Content-Type header manipulation.

Proof-of-concept exploit for CVE-2024-10410: unrestricted file upload in Online Hotel Reservation System. Demonstrates bypass of image validation via…

CVE-2017-7269 to webshell or shellcode loader

st2-046-poc CVE-2017-5638

CVE-2022-26134 Confluence OGNL Injection POC

Public PoC for CVE-2025-25257: FortiWeb pre-auth SQLi to RCE