
vulmap
Web vulnerability scanner and exploitation tool with POC/EXP modes for known CVEs across webapps such as Weblogic, Shiro, Struts2, and Tomcat;…

Web vulnerability scanner and exploitation tool with POC/EXP modes for known CVEs across webapps such as Weblogic, Shiro, Struts2, and Tomcat;…

CVE-2026-49268 — Analysis and Remediation of an LDAP Injection Authentication Bypass Vulnerability

Analysis of two authentication bypass techniques for Apache Shiro (CVE-2020-17523) with a reproducible exploit environment and detailed root cause…

Shiro RememberMe 1.2.4 反序列化 漏洞

Exploit tool for CVE-2023-46604 in Apache ActiveMQ, supporting out-of-band exploitation, custom bytecode execution, and Shiro ini configuration for…

Apache Shiro CVE-2022-32532

一个针对shiro反序列化漏洞(CVE-2016-4437)的快速利用工具/A simple tool targeted at shiro framework attacks with ysoserial.

CVE-2020-13933 靶场: shiro 认证绕过漏洞

Python utility for automating CVE-2024-4956 path traversal exploitation with mass file extraction, plus custom Hashcat module for cracking Apache…

Python POC to Exploit CVE-2016-4437 Apache Shiro Deserialization Vulnerability Due to Hardcode Encryption Key

Simple hash cracker for Apache Shiro hashes written in Golang. Useful for exploiting CVE-2024-4956.


若依4.2 (Shiro 1.4.1) Shiro-721 (CVE-2019-12422)漏洞复现环境

Minimal Java web application to reproduce CVE-2022-32532, an Apache Shiro RegExPatternMatcher authentication bypass via newline characters in URLs.

Exploit code for CVE-2020-11989, an Apache Shiro authentication bypass vulnerability, enabling remote attackers to bypass security controls in web…

Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security…

Java security framework providing authentication, authorization, cryptography, and session management APIs to secure any application from mobile to…