Fetching description from NVD…
Show 2 repositories
vulhub/H2-database/CVE-2022-23221
Vulhub h2database/CVE-2022-23221: H2 Database Console JDBC URL RCE (CVE-2022-23221), run with Isoloom
Public proof-of-concept exploits for fresh CVEs, tracked from GitHub around the clock. Filter, search and stay ahead of attackers.
monitoring live361 results
Fetching description from NVD…
vulhub/H2-database/CVE-2022-23221
Vulhub h2database/CVE-2022-23221: H2 Database Console JDBC URL RCE (CVE-2022-23221), run with Isoloom
Fetching description from NVD…
Grafana Unauthorized arbitrary file reading vulnerability
A exploit tool for Grafana Unauthorized arbitrary file reading vulnerability (CVE-2021-43798), it can burst plugins / extract secret_key / decrypt data_source …
This is a proof-of-concept exploit for Grafana's Unauthorized Arbitrary File Read Vulnerability (CVE-2021-43798).
CVE-2021-43798 - Grafana 8.x Path Traversal (Pre-Auth)
Grafana Arbitrary File Reading Vulnerability
CVE-2021-43798:Grafana 任意文件读取漏洞
grafana CVE-2021-43798任意文件读取漏洞POC,采用多插件轮训检测的方法,允许指定单URL和从文件中读取URL
CVE-2021-43798 Grafana 任意文件读取漏洞 POC+参数
Fetching description from NVD…
POC&EXP for GlassFish<4.1.1(not including 4.1.1).
Vulhub glassfish/CVE-2017-1000028: GlassFish 4.1 Admin Console Arbitrary File Read (CVE-2017-1000028), run with Isoloom
Fetching description from NVD…
CVE-2021-22205& GitLab CE/EE RCE
GitLab CE/EE Preauth RCE using ExifTool
Pocsuite3 For CVE-2021-22205
CVE-2021-22205 Unauthorized RCE
CVE-2021-22205 Gitlab 未授权远程代码执行漏洞 EXP, 移除了对djvumake & djvulibre的依赖,可在win平台使用
CVE-2021-22205 RCE
CVE-2021-22205 检测脚本,支持getshell和命令执行
Fetching description from NVD…
PoC + Docker Environment for Python PIL/Pillow Remote Shell Command Execution via Ghostscript CVE-2018-16509
CVE-2018-16509 (Ghostscript contains multiple -dSAFER sandbox bypass vulnerabilities)
CVE-2018-16509 Docker Playground - Ghostscript command execution
cve-2018-16509
Vulhub ghostscript/CVE-2018-16509: Ghostscript -dSAFER Sandbox Bypass (CVE-2018-16509), run with Isoloom
Fetching description from NVD…
Tool check: CVE-2021-41773, CVE-2021-42013, CVE-2020-17519
Apache Flink 目录遍历漏洞批量检测 (CVE-2020-17519)
[CVE-2020-17519] Apache Flink RESTful API Arbitrary File Read
Apache Flink Directory Traversal (CVE-2020-17519) Nmap NSE Script
CVE-2020-17519; Apache Flink 任意文件读取; 批量检测
CVE-2020-17519 Cheetah
CVE-2020-17519
Fetching description from NVD…
Elasticsearch 1.4.0 < 1.4.2 Remote Code Execution exploit and vulnerable container
cve-2015-1427
To test elasticsearch vulnerabillity on newer version of debian
Vulhub elasticsearch/CVE-2015-1427: Elasticsearch 1.4.2 Groovy sandbox escape, run with Isoloom
Fetching description from NVD…
POC Code to exploite CVE-2014-3120
Demonstration of CVE-2014-3120
Vulhub elasticsearch/CVE-2014-3120: Elasticsearch MVEL Dynamic Script RCE (CVE-2014-3120), run with Isoloom
Fetching description from NVD…
Basic code for creating the Alibaba FastJson + Spring gadget chain, as used to exploit Apache Dubbo in CVE-2019-17564 - more information available at https://w…
CVE-2019-17564:Apache Dubbo反序列化漏洞
CVE-2019-17564 Apache Dubbo deserialization RCE
CVE-2019-17564 : Apache Dubbo Deserialization Remote Code Execution
Vulhub dubbo/CVE-2019-17564: Apache Dubbo HTTP Protocol Deserialization (CVE-2019-17564), run with Isoloom
Fetching description from NVD…
Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002)
💀Proof-of-Concept for CVE-2018-7600 Drupal SA-CORE-2018-002
Exploit for Drupal 7 <= 7.57 CVE-2018-7600
CVE-2018-7600 Drupal RCE
CVE-2018-7600 - Drupal 7.x RCE
Exploit for CVE-2018-7600.. called drupalgeddon2,
CVE-2018-7600 POC (Drupal RCE)
CVE-2018-7600 Drupal Drupalgeddon 2 远程代码执行漏洞利用脚本
Fetching description from NVD…
An rewritten POC on the CVE-2014-3704
This code is taken from "Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User)" and was converted to Python 3 to suit the exercise in Academy for M…
CVE-2014-3704 aka Drupalgeddon - Form-Cache Injection Method
Audit de sécurité Black Box d'un serveur Drupal 7. Démonstration d'une Kill Chain complète : Injection SQL (CVE-2014-3704) ➔ RCE ➔ Reverse Shell ➔ Escalade ver…
Full home-lab penetration test of Rapid7's Metasploitable3 (Ubuntu 14.04) from Parrot OS. Covers recon, Drupalgeddon (CVE-2014-3704) RCE, SSH credential reuse,…
Vulhub drupal/CVE-2014-3704: Drupal 7.31 Drupalgeddon SQL Injection (CVE-2014-3704), run with Isoloom
Fetching description from NVD…
PoC for CVE-2022-34265 (Django)
PoC for CVE-2022-34265
CVE-2022-34265 Vulnerability
Vulhub django/CVE-2022-34265: Django Trunc and Extract SQL Injection (CVE-2022-34265), run with Isoloom
Fetching description from NVD…
Case study and POC of CVE-2017-12635: Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation
This tool exploits two critical vulnerabilities in Apache CouchDB: | CVE | Description | Severity | |-----|-------------|----------| | **CVE-2017-12635** | Pr…
Vulhub couchdb/CVE-2017-12635: Apache CouchDB Privilege Escalation (CVE-2017-12635), run with Isoloom
Fetching description from NVD…
Redux Python3 Version of CVE-2010-2861
Vulhub coldfusion/CVE-2010-2861: Adobe ColdFusion 8 Directory Traversal (CVE-2010-2861), run with Isoloom
Fetching description from NVD…
CVE-2022-46169 Cacti remote_agent.php Unauthenticated Command Injection.
This is a exploit of CVE-2022-46169 to cacti 1.2.22. This exploit allows through an RCE to obtain a reverse shell on your computer.
PoC for CVE-2022-46169 - Unauthenticated RCE on Cacti <= 1.2.22
This is poc of CVE-2022-46169 authentication bypass and remote code execution
Exploit to CVE-2022-46169 vulnerability
Cacti Unauthenticated Command Injection
RCE POC for CVE-2022-46169
Fixed exploit for CVE-2022-46169 (originally from https://www.exploit-db.com/exploits/51166)
Fetching description from NVD…
Shellshock exploit + vulnerable environment
Python Scanner for "ShellShock" (CVE-2014-6271)
Vulnerability as a service: showcasing CVS-2014-6271, a.k.a. Shellshock
Shellshock exploit aka CVE-2014-6271
shellshock CVE-2014-6271 CGI Exploit, Use like Openssh via CGI
A python script to enumerate CGI scripts vulnerable to CVE-2014-6271 on one specific server
Android app to scan for bash Vulnerability - CVE-2014-6271 also known as Shellshock
Patch for CVE-2014-6271
The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.
Vulhub appweb/CVE-2018-8715: Appweb Digest Authentication Bypass (CVE-2018-8715), run with Isoloom
Fetching description from NVD…
Apisix系列漏洞:未授权漏洞(CVE-2021-45232)、默认秘钥(CVE-2020-13945)批量探测。
Vulhub apisix/CVE-2020-13945: Apache APISIX Default Admin Token RCE (CVE-2020-13945), run with Isoloom
Fetching description from NVD…
Alibaba-Nacos-Unauthorized/ApacheDruid-RCE_CVE-2021-25646/MS-Exchange-SSRF-CVE-2021-26885/Oracle-WebLogic-CVE-2021-2109_RCE/RG-CNVD-2021-14536/RJ-SSL-VPN-Ultra…
Apache Druid 远程代码执行;检测脚本
Apache Druid remote code execution vulnerability - Apache Druid 远程代码执行漏洞利用 CVE-2021-25646
CVE-2021-25646 Apache Druid 远程代码执行 漏洞检测和利用工具
CVE-2021-25646 Apache Druid 远程代码执行漏洞 Wker脚本
CSharp CVE-2021-25646-GUI
Fetching description from NVD…
Apache CXF SSRF CVE-2024-28752
Vulhub apache-cxf/CVE-2024-28752: Apache CXF Aegis DataBinding SSRF (CVE-2024-28752), run with Isoloom
Fetching description from NVD…
Achieving a Reverse Shell Exploit for Apache ActiveMQ (CVE_2023-46604)
Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588)
ActiveMQ RCE (CVE-2023-46604) 回显利用工具
CVE-2023-46604
This script leverages CVE-2023046604 (Apache ActiveMQ) to generate a pseudo shell. The vulnerability allows for remote code execution due to unsafe deserializa…
CVE-2023-46604 Apache ActiveMQ RCE exp 基于python
Fetching description from NVD…
Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588)
ActiveMQ系列漏洞探测利用工具,包括ActiveMQ 默认口令漏洞及ActiveMQ任意文件写入漏洞(CVE-2016-3088),支持批量探测利用。
ActiveMQ_putshell直接获取webshell
Apache ActiveMQ Remote Code Execution Exploit
Apache ActiveMQ PUT RCE Scan
A Python-based Exploit Script for CVE-2016-3088
mitmproxy is an interactive, SSL/TLS-capable intercepting proxy. In mitmproxy 7.0.2 and below, a malicious client or server is able to perform HTTP request smuggling attacks through mitmproxy. This means that a malicious client/server could smuggle a request/response through mitmproxy as part of another request/response's HTTP message body. While a smuggled request is still captured as part of another request's body, it does not appear in the request list and does not go through the usual mitmproxy event hooks, where users may have implemented custom access control checks or input sanitization. Unless one uses mitmproxy to protect an HTTP/1 service, no action is required. The vulnerability has been fixed in mitmproxy 7.0.3 and above.
secDevLabs Golden Hat Society: mitmproxy 5.3.0 request smuggling, CVE-2021-39214 (OWASP A06), run with Isoloom
Fetching description from NVD…
Forensic audit of mcp-remote: seven OAuth trust-boundary advisories, five CVE records (CVE-2026-51994/51995/51996/51997/52001). Server-selected request path (C…
Fetching description from NVD…
POC for CVE-2022-47966 affecting multiple ManageEngine products
Python scanner for CVE-2022-47966. Supports ~10 of the 24 affected products.
The manage engine mass loader for CVE-2022-47966
Run on your ManageEngine server
PoC for cve-2022-47966
Sources: public PoC repositories on GitHub (nomi-sec/PoC-in-GitHub), descriptions and scores from NVD / CVE.org. Exploit code is third-party; review before running.