
CVE-2023-38545-libcurl-SOCKS5-heap-buffer-overflow
Proof-of-concept exploit for CVE-2023-38545, a heap buffer overflow in libcurl's SOCKS5 proxy handshake triggered via a malicious HTTP 301 redirect…

Proof-of-concept exploit for CVE-2023-38545, a heap buffer overflow in libcurl's SOCKS5 proxy handshake triggered via a malicious HTTP 301 redirect…

Flexense HTTP Server <= 10.6.24 - Denial Of Service Exploit

A critical pre-authentication Remote Code Execution (RCE) flaw in Oracle E-Business Suite (versions 12.2.3 - 12.2.14) allows attackers to gain full…

This repository contains a Proof of Concept (PoC) demonstrating the Double Free vulnerability (CVE-2026-23918) in Apache HTTP Server 2.4.66…

Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of…

Playground to experiment with different behavior on patched/unpatched Kestrel for the CVE-2025-55315 HTTP smuggling vulnerability

Proof-of-concept and technical write-up for CVE-2026-73315, an SSRF in XenForo's PayPal REST webhook handler allowing blind server-side HTTP requests.

Proof-of-concept exploit for CVE-2022-42248, a stored cross-site scripting vulnerability in QlikView Ajax Client allowing remote attackers to execute…

Scanner for CVE-2024-40725 Apache HTTP Server source-code disclosure; probes direct and subrequest paths, fingerprints affected versions, and outputs…

Intentionally vulnerable Log4j 2.14.1 HTTP service for hands-on practice with CVE-2021-44228 (Log4Shell) in an isolated sandbox environment.

CVE-2019-10092 Docker - Apache HTTP Server

Proof-of-concept exploit for CVE-2021-32099, a SQL injection vulnerability in Pandora FMS, demonstrating session hijacking via crafted HTTP requests.

Docker-based lab for reproducing CVE-2021-41773 (Apache HTTP Server 2.4.49) through controlled path traversal and file disclosure using a custom…

Proof-of-concept exploit script for CVE-2024-24919 that scans target URLs via HTTP POST requests, analyzes responses for unauthorized access or data…

Proof-of-concept exploit for Apache HTTP Server mod_proxy SSRF vulnerability (CVE-2021-40438) affecting versions <= 2.4.48, enabling server-side…

Proof-of-concept exploit for CVE-2017-7529, an integer overflow in Nginx cache that leaks backend server IPs and sensitive information via crafted…

Exploit for CVE-2020-11547: unauthenticated information disclosure in PRTG Network Monitor via crafted HTTP requests to /public/login.htm or…

Burp Bounty profile for detecting Apache Text4Shell (CVE-2022-42889), an RCE in Commons Text 1.5-1.9, by scanning HTTP requests.