
Apache-APISIX-CVE-2022-24112
Apache APISIX Remote Code Execution (CVE-2022-24112) proof of concept exploit

Apache APISIX Remote Code Execution (CVE-2022-24112) proof of concept exploit

Proof-of-concept for CVE-2025-63406 in GroupOffice, demonstrating API-based object manipulation and authentication flow for vulnerability analysis…

HopLa Burp Suite Extender plugin - Brings AI capabilities, autocompletion support, and a set of useful payloads to Burp Suite

An intentionally designed broken web application based on REST API.

Proof-of-concept exploit for CVE-2026-24134, a Broken Object Level Authorization vulnerability in StudioCMS, demonstrating unauthorized access to…

End to End testing of Web, API, Cloud, Events and Security

GLPI Privilege Escalation via authtype Manipulation PoC - CVE-2026-53625. Ethical PoC for the GLPI vulnerability allowing a Technician to take full…

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

A simple server to host the valid, revoked, and expired certificates required by Section 2.2 of the CA/Browser Forum Baseline Requirements.

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

Reproducer for CVE-2026-46588: Apache Camel camel-couchdb CouchDb* header injection (operation confusion) subverting a write-only endpoint into read…

ChilliCream Nitro GraphQL version 28.0.13 is vulnerable to multiple Stored Cross Site Scripting (XSS) Vulnerabilities

The vulnerability exists in the Student Payment API. The application fails to properly validate whether the user requesting a receipt is authorized…

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

a Damn Vulnerable Serverless Application

Burp Extension for collaboration in Faraday

Insecure Permissions WeDayCare