Langflow 在对用户提交的“验证代码”做 AST 解析和编译时,在未做鉴权与沙箱限制的情况下调用了 Python 的 compile()/exec()(以及在编译阶段会评估函数默认参数与装饰器),攻击者可把恶意载荷放在参数默认值或装饰器里,借此在服务器上下文中执行任意语句(反弹 shell、下载器、横向移动等)
CVE-2025-61882: Oracle E-Business Suite RCE Scanner and Exploit
path traversal tool based on cve 2025 8088 vurnelability
Detects Oracle E-Business Suite (CVE-2025-61882). Detection: multi-tier checks — fingerprinting, version checks, endpoint & SSRF tests, timing analysis & controlled exploitation 4 high-confidence results. Default = safe fingerprinting only. Set aggressive=true 2 enable active/probing checks use w/caution. Provided By BattalionX BattalionX@proton.me
Redux Python3 Version of CVE-2010-2861
overwrites binary allowing priv esc from dev to worker node
Path traversal tool based on cve-2025-8088 vulnerability
A POC exploit for WinRAR vulnerability (CVE-2025-8088) affecting versions 7.12 and lower
PoC for CVE-2025-10230 - Samba WINS hook command injection
We are presented with a security alert indicating the detection of the Follina (CVE-2022-30190) vulnerability. A malicious Word document triggered msdt.exe execution, suggesting possible remote code execution on the host JonasPRD. Our task is to investigate the alert, confirm exploitation, assess impact, and recommend remediation.
path traversal tool based on cve-2025-8088
The default configuration of LDAP on FortiOS v6.0.x to v6.2.0 does not check server identity for LDAP/S leading to MITM attacks. This PoC demos full exfiltration of credentials sent on the local subnet to an LDAP server that is easily impersonated.
A critical pre-authentication Remote Code Execution (RCE) flaw in Oracle E-Business Suite (versions 12.2.3 - 12.2.14) allows attackers to gain full control over vulnerable servers via malicious HTTP requests - now actively exploited in the wild.
Oracle WebLogic WLS-WSAT Remote Code Execution Exploit (CVE-2017-10271)
PoCs for CVE-2025-57199, CVE-2025-57200, CVE-2025-57201, CVE-2025-57202, and CVE-2025-57203
CVE-2025-60378 — Stored HTML Injection in RISE — Ultimate Project Manager & CRM < 3.9.4 (Invoices & Messaging)
CVE-2025-8088 based path traversal tool