
CVE-2022-22954
CVE-2022-22954 VMware Workspace ONE Access freemarker SSTI 漏洞 命令执行、批量检测脚本、文件写入

CVE-2022-22954 VMware Workspace ONE Access freemarker SSTI 漏洞 命令执行、批量检测脚本、文件写入

Proof-of-concept exploit for CVE-2023-3824 (PHP phar deserialization) enabling remote code execution via crafted phar archive and reverse shell…

cve-2016-16113

SambaCry (CVE-2017-7494) exploit for Samba | bind shell without Metasploit

Download Plugin <= 2.2.8 - Authenticated (Administrator+) Arbitrary File Upload

Ultimate Addons for Contact Form 7 <= 3.5.12 - Authenticated (Administrator+) Arbitrary File Upload via 'save_options'

Make Connector <= 1.5.10 - Authenticated (Administrator+) Arbitrary File Upload

CIBELES AI <= 1.10.8 - Unauthenticated Arbitrary File Upload

Flex QR Code Generator <= 1.2.6 - Unauthenticated Arbitrary File Upload

All-in-One WP Migration and Backup <= 7.86 - Authenticated (Administrator+) Arbitrary PHP Code Injection

Migration,Backup, Staging – WPvivid <= 0.9.112 - Authenticated (Admin+) Arbitrary File Upload via wpvivid_upload_file

This repository contains a Proof-of-Concept (PoC) exploit for the Baron Samedit vulnerability (CVE-2021-3156). The exploit demonstrates privilege…

Automated exploitation toolkit for CVE-2025-24813 targeting Apache Tomcat insecure session deserialization. Features multi-target scanning, gadget…

A Proof-Of-Concept Exploit for CVE-2021-44228 vulnerability.

Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution

Exploit for CVE-2021-3129 targeting Laravel Ignition 2.5.1, leveraging phpggc for remote code execution via malicious log files.

CVE-2021-26295-POC 利用DNSlog进行CVE-2021-26295的漏洞验证。 使用 poc:将目标放于target.txt后运行python poc.py即可。(Jdk环境需<12,否则ysoserial无法正常生成有效载荷) exp:python exp.py…

Proof-of-concept exploit for Log4j 2.17.0 RCE (CVE-2021-44832) using JNDI injection with malicious configuration file deployment.