
Preproduce-CVE-2021-41773
PoC and exploit for CVE-2021-41773 path traversal in Apache HTTP Server 2.4.49, with Docker setup and curl-based exploitation commands for file…

PoC and exploit for CVE-2021-41773 path traversal in Apache HTTP Server 2.4.49, with Docker setup and curl-based exploitation commands for file…

Sigma rule for detecting CVE-2025-29927 exploitation via suspicious x-middleware-subrequest HTTP headers in Next.js applications, with detection…

Proof-of-concept exploit for CVE-2018-6574, a Go language vulnerability allowing remote code execution via crafted HTTP requests.

https & http

Python script to detect CVE-2024-41713 directory traversal in Apache HTTP Server, providing response snippets for verification. For educational and…

Comprehensive Java utility library providing modules for cryptography, HTTP client, caching, JSON, scripting, and captcha generation, simplifying…

Detects subdomain takeover vulnerabilities by analyzing DNS records and HTTP responses. Automatically identifies takeover-prone subdomains for…

RFC6265-compliant cookie parsing and CookieJar management library for Node.js, with CVE-2023-26136 security patch. Supports cookie creation,…

Network packets & HTTP sockets captor || Alternative of Burp Collaborator

Python-based scanner that detects debug mode misconfigurations in web applications using multiple HTTP methods and fingerprinting techniques to…

Command-line tool and library for transferring data using URL syntax, supporting various protocols including HTTP, FTP, and more.

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

Terminal-based HTTP intercepting proxy with TUI for capturing, inspecting, and modifying requests in real time, plus a Repeater for resending and…

Minimal reproduction of CVE-2026-22732 — Spring Security HTTP headers silently dropped

Proof-of-concept and technical write-up for CVE-2026-73315, an SSRF in XenForo's PayPal REST webhook handler allowing blind server-side HTTP requests.

Proof-of-concept exploit scripts for CVE-2026-63642 and CVE-2026-63643, SSRF vulnerabilities in MagicMirror²'s Calendar module allowing…

Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content

Behavior-preserving fix for CVE-2025-60876 HTTP header injection in BusyBox wget, with proof-of-concept, percent-encoding patch, and upstream…