


Proof-of-concept exploit for CVE-2024-4577, a PHP CGI argument injection vulnerability enabling remote code execution via crafted HTTP requests.


Dynamically invoke arbitrary unmanaged code

Proof-of-concept for CVE-2026-75898, an SSRF in RAGFlow's Invoke component. Demonstrates the vulnerability with unmodified source, includes E2E…

simple application with a (unreachable!) CVE-2022-45688 vulnerability