


A vulnerable version of Rails that follows the OWASP Top 10

Exploit for CVE-2022-22965 (Spring4Shell) targeting Spring Framework versions vulnerable to remote code execution via classLoader manipulation.

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

Proof-of-concept exploit for CVE-2023-4634, a remote code execution vulnerability in the WordPress Media Library Assistant plugin. Includes a…

CVE-2019-10172 PoC and Possible mitigations

Proof-of-concept exploit for CVE-2024-24824 demonstrating how an arbitrary class loading primitive can be transformed into remote code execution on…

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

a fast check, if your server could be vulnerable to CVE-2021-44228

Bookea-tu-Mesa is vulnerable to SQL Injection

Sean's Surf & Skate Co. — Spring Boot storefront with a vulnerable SnakeYAML dep (CVE-2022-1471) for Seal Security demos

Scanners for Jar files that may be vulnerable to CVE-2021-44228

Static Analyzer for Starknet smart contracts

Proof-of-concept exploit for authenticated PHP code injection in ISPConfig <= 3.2.11, enabling remote code execution via unsanitized language file…

Python source code auditing and static analysis on a large scale

Static analysis scanner for CVE-2020-11023 XSS vulnerabilities in JavaScript. Detects vulnerable jQuery versions and dangerous DOM manipulation…

Bash and PowerShell scripts to scan a local filesystem for Log4j .jar files which could be vulnerable to CVE-2021-44228 aka Log4Shell.