Exploits for CNEXT (CVE-2024-2961), a buffer overflow in the glibc's iconv()
☆505Sep 30, 2024Updated last year
Alternatives and similar repositories for cnext-exploits
Users that are interested in cnext-exploits are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Generates a `php://filter` chain that adds a prefix and a suffix to the contents of a file.☆245Oct 8, 2024Updated last year
- A CLI to exploit parameters vulnerable to PHP filter chain error based oracle.☆335Jun 2, 2024Updated 2 years ago
- lightyear is a tool to dump files in tedious (blind) conditions using PHP filters☆116Jun 23, 2025Updated last year
- ☆98Sep 2, 2024Updated last year
- MySQL Fake Server use to help MySQL Client File Reading and JDBC Client Java Deserialize☆1,378Nov 18, 2021Updated 4 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Some ReadObject Sink With JDBC☆245May 8, 2024Updated 2 years ago
- ☆1,065Jan 23, 2023Updated 3 years ago
- 一款支持自定义的 Java 内存马生成工具|A customizable Java in-memory webshell generation tool.☆2,228Aug 21, 2025Updated 11 months ago
- Java Vulnerability Exploitation Platform☆2,142Updated this week
- A (small) web exploit framework☆98Dec 26, 2025Updated 7 months ago
- 80+ Gadgets(30 More than ysoserial). JNDI-Injection-Exploit-Plus is a tool for generating workable JNDI links and provide background serv…☆881Jun 24, 2024Updated 2 years ago
- A rouge mysql server supports reading files from most mysql libraries of multiple programming languages.☆771Dec 2, 2022Updated 3 years ago
- 专为CTF设计的Jinja2 SSTI全自动绕WAF脚本 | A Jinja2 SSTI cracker for bypassing WAF, designed for CTF☆1,299Updated this week
- ☆350Jan 24, 2023Updated 3 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- 高性能 HTTP 正向代理工具 | A high-performance http tunneling tool☆2,791Jul 14, 2026Updated last month
- ZKar is a Java serialization protocol analysis tool implement in Go.☆653Apr 19, 2026Updated 3 months ago
- This repository contains PoC for CVE-2024-7965. This is the vulnerability in the V8 that occurs only within ARM64.☆49Sep 16, 2024Updated last year
- 一款专注于 Java 主流 Web 中间件的内存马快速生成工具,致力于简化安全研究人员和红队成员的工作流程,提升攻防效率☆1,574Updated this week
- dotnet 反序列化学习笔记☆522Oct 19, 2023Updated 2 years ago
- some fun php exploits☆81Nov 12, 2024Updated last year
- PoC & Exploit for CVE-2025-32023 / PlaidCTF 2025 "Zerodeo"☆216Jul 6, 2025Updated last year
- cve-2022-34169 延伸出的Jdk Xalan的payload自动生成工具,可根据不同的Jdk生成出其所对应的xslt文件☆94Jan 17, 2023Updated 3 years ago
- CVE-2023-34992: Fortinet FortiSIEM Command Injection Proof of Concept Exploit☆27May 21, 2024Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- A CAT called tabby ( Code Analysis Tool )☆1,656Jan 17, 2026Updated 6 months ago
- ☆161Jul 10, 2024Updated 2 years ago
- A powerful JNDI injection exploitation framework that supports RMI, LDAP and LDAPS protocols, including various bypass methods for high-v…☆600May 4, 2026Updated 3 months ago
- a rep for documenting my study, may be from 0 to 0.1☆2,295Mar 25, 2026Updated 4 months ago
- 《深入JDBC安全:特殊URL构造与不出网反序列化利用技术揭秘》对应 研究总结项目 "Deep Dive into JDBC Security: Special URL Construction and Non-Networked Deserialization Explo…☆594Feb 7, 2026Updated 6 months ago
- 纯 Java 实现的 MySQL Fake Server | 支持 GUI 版和命令行版 | 支持反序列化和文件读取的利用方式 | 支持常见的 GADGET 和自定义 GADGET 数据 | 根据目标环境自动生成匹配的 PAYLOAD | 支持 PGSQL 和 DERBY …☆839Sep 18, 2023Updated 2 years ago
- WebSocket 内存马/Webshell,一种新型内存马/WebShell技术☆1,491Apr 10, 2023Updated 3 years ago
- Exploit for the vulnerability CVE-2024-43044 in Jenkins☆186Oct 2, 2024Updated last year
- Universal local privilege escalation Proof-of-Concept exploit for CVE-2024-1086, working on most Linux kernels between v5.14 and v6.6, in…☆2,454Apr 17, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- CTF-Java-Gadget专注于收集CTF中Java赛题的反序列化片段☆289Dec 13, 2024Updated last year
- 抽离出 utf-8-overlong-encoding 的序列化逻辑,实现 2 3 字节加密序列化数组☆141Mar 11, 2024Updated 2 years ago
- Fastjson姿 势技巧集合☆1,861Oct 20, 2023Updated 2 years ago
- A neo4j procedure for tabby☆136May 17, 2025Updated last year
- PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.☆3,873Sep 29, 2025Updated 10 months ago
- PoC for CVE-2023-4911☆392Oct 4, 2023Updated 2 years ago
- 通过端口复用直接进行正向socks5代理(非防火墙分流)☆116Dec 17, 2024Updated last year