
SecurityNotFound
Stealthy PHP webshell disguised as a 404 error page with AJAX console, hidden command execution via Referrer header, and preconfigured actions for…

Stealthy PHP webshell disguised as a 404 error page with AJAX console, hidden command execution via Referrer header, and preconfigured actions for…

Multi-domain HTTP 403 bypass scanner that tests header manipulation techniques to discover hidden access paths on web servers, supporting bulk domain…

CVE-2026-73034 — DB-GPT v0.8.1 unauth path traversal → arbitrary file write as root via user-id header. Verified + fix diff

Proof-of-concept exploit for Apache Struts2 remote code execution vulnerability CVE-2017-5638, demonstrating exploitation via crafted Content-Type…

Snipe-IT PoC exploit for CVE-2025-59712 and CVE-2025-59713

Public PoC for CVE-2025-25257: FortiWeb pre-auth SQLi to RCE

Bash script that adds custom HTTP headers to requests for bulk testing of 403 bypass techniques on web applications.

Python PoC exploiting CVE-2025-27636, an Apache Camel header injection RCE, supporting command execution, file reads, and reverse shell payloads.

JSON Web Token Hack Toolkit

Proof-of-concept exploit for CVE-2026-21003 demonstrating JWT authentication bypass by omitting the kid header and using the 'none' algorithm to…

Fix host header error in zaproxy

Proof-of-concept exploit for CVE-2024-10410: unrestricted file upload in Online Hotel Reservation System. Demonstrates bypass of image validation via…

Exploit tool that transforms SMTP header injection into remote code execution with self-propagating worm capabilities, featuring persistence…

PoC for triggering buffer overflow via CVE-2020-0796

Icecast Header Overwrite buffer overflow RCE < 2.0.1 (Win32)

st2-046-poc CVE-2017-5638

Reproducer for CVE-2026-33454: Apache Camel camel-mail header injection to RCE via camel-exec

A PoC Exploit for CVE-2024-3105 - The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress Remote Code Execution (RCE)