
PENTEST-LAB
Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

PoC for CVE-2019-19844(https://www.djangoproject.com/weblog/2019/dec/18/security-releases/)

an impacket-dependent script exploiting CVE-2019-1040

a small utility to generate a cookie in order to exploit a grafana vulnerability (CVE-2018-15727)


SpringBlade框架JWT认证的漏洞检测工具

A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor


A small PoC for the Keycloak vulnerability CVE-2023-0264

WordPress Plugin MasterStudy LMS 2.7.5 - Unauthenticated Admin Account Creation

The script in this repository only checks whether the vulnerabilities specified in the Ivanti Connect Secure product exist.

Apache HTTP Server versions 2.4.35 – 2.4.63 are vulnerable to a client certificate authentication bypass when TLS 1.3 session resumption is used…

Utilities for exploiting vulnerability CVE-2022-40684 (FortiOS / FortiProxy / FortiSwitchManager - Authentication bypass on administrative interface).

PoC Exploit for CVE-2018-8820

CVE-2026-8181 PoC: Burst Statistics (3.4.0–3.4.1.1) authentication bypass. Python tool — single & multi-target scans, threaded workers, TXT reports.…

Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a…