
CVE-2026-36958
Proof-of-concept for CVE-2026-36958, a denial-of-service vulnerability in U-SPEED Router firmware that exhausts resources via concurrent HTTP…

Proof-of-concept for CVE-2026-36958, a denial-of-service vulnerability in U-SPEED Router firmware that exhausts resources via concurrent HTTP…

Proof-of-concept exploit for CVE-2022-2414, an XML external entity (XXE) vulnerability in FreeIPA, enabling remote file retrieval via crafted HTTP…

Analyzes a specific CVE in WeChat OAuth handler, identifying unbounded HTTP response reads leading to denial of service, with remediation guidance.

Passive HTTP metadata auditor for CVE-2026-23918 exposure triage

Proof of concept exploit for CVE-2021-42697: Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing…

Proof-of-concept exploit for CVE-2025-55315 (.NET HTTP Request Smuggling). Demonstrates how improperly parsed chunked encoding lets attackers smuggle…

Critical heap buffer overflow vulnerability in the handle_trace_request and parse_trace_request functions of the Fluent Bit HTTP server.

Proof-of-concept for CVE-2026-21962, a critical unauthenticated remote vulnerability in Oracle HTTP Server and WebLogic Proxy Plug-in, demonstrating…

Path Traversal Apache HTTP Server 2.4.49/2.4.50

Functional exploit for CVE-2025-29927, a critical Next.js middleware authorization bypass. Sends crafted HTTP requests with the…

CVE Repository for HTTP DeSynchronization Attacks

An unauthenticated attacker can send an HTTP request with an "Accept-Encoding" HTTP request header triggering a double free in the unknown…

Proof-of-concept scanner for CVE-2025-62168, a Squid Proxy information disclosure vulnerability that exposes HTTP authentication credentials,…

Proof-of-concept exploit for Apache HTTP Server path traversal vulnerability (CVE-2021-41773) enabling file disclosure and source code leakage…

Nuclei template for detecting CVE-2024-28995, a directory traversal vulnerability in Serv-U FTP server, enabling file read via crafted HTTP requests.

Python script to verify SSRF and content spoofing vulnerabilities (CVE-2025-58179) in Astro's `/_image` endpoint, with automated PoC URL generation…

Proof-of-concept script to detect CVE-2024-9466 by checking HTTP responses for a specific debug file path on target URLs.

Working exploit for CVE-2025-23167 – HTTP request smuggling in vulnerable Node.js 20.x versions before 20.19.2