
CaptainHook
Traces user inputs to detect injection vulnerabilities in Java methods via JDWP and Frida, identifying potential command and SQL injection points.

Traces user inputs to detect injection vulnerabilities in Java methods via JDWP and Frida, identifying potential command and SQL injection points.

CVE-2026-44289, CVE-2026-44290, CVE-2026-44291, CVE-2026-44292, CVE-2026-44294, CVE-2026-44295 - protobuf.js

PHPMailer < 5.2.18 Remote Code Execution

Build and query a graph database representation of source code

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

Apache Karaf XXE Vulnerability (CVE-2018-11788)

A bit of research around CVE-2024-52301

awslabs/sockeye Code injection via unsafe YAML loading CVE-2021-43811

CVE-2026-34038: Authenticated Remote Command Injection in Coolify

Docker-based lab to reproduce CVE-2017-9841, a remote code execution vulnerability in PHPUnit's eval-stdin.php when installed under a web root.

Educational lab demonstrating CVE-2025-55182: Critical RCE in React Server Components via prototype pollution in the Flight protocol

CVE-2026-63030: WordPress REST batch-endpoint array desync. Mechanism, detection, mitigation, and a safe reproduction lab.