
Some-Tools
Some Pentest Tools. Install and keep up to date some pentesting tools. I used this to pass my OSCP exam.

Some Pentest Tools. Install and keep up to date some pentesting tools. I used this to pass my OSCP exam.

The issue is due to the fact that when installing a package, Golang will build native extensions. This can be used to pass additional flags to the…

Step-by-step technical analysis of CVE-2019-1698, a WordPress plugin SQL injection vulnerability, with code diff review, vulnerable function…

Exploit for CVE-2019-9081 with payload generation. Pass payload as parameter to trigger the vulnerability.

HTTP Request Smuggling over HTTP/2 Cleartext (h2c)

Tomcat常见漏洞GUI利用工具。CVE-2017-12615 PUT文件上传漏洞、tomcat-pass-getshell 弱认证部署war包、弱口令爆破、CVE-2020-1938 Tomcat AJP文件读取/包含

Exploit for nginx heap buffer overflow (CVE-2026-42533) providing pre-auth RCE via two-pass capture clobbering. Includes info leak, heap spray, and…

Spring Cloud Gateway Actuator API SpEL表达式注入命令执行(CVE-2022-22947) 注入哥斯拉内存马

CVE-2022-22978 POC Project

This is a proof of concept for CVE-2023-24610

Python Exploit for CVE: 2018-9276

The code for personally reproducing the corresponding vulnerability

Proof-of-concept exploit for CVE-2025-29927, demonstrating authentication bypass in Next.js middleware via the x-middleware-subrequest header, with…

Lab + writeup for CVE-2026-44166: PocketBase OAuth2 account pre-hijacking via unvalidated createData.email

Proof-of-concept exploit for CVE-2024-21683, a remote code execution vulnerability in Atlassian Confluence. Executes a JavaScript payload against…

This is a PoC for CVE-2023-27372 and spawns a fully interactive shell.

Strapi Framework, 3.0.0-beta.17.4