
vuln-bank
Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

Open-source Interactive Application Security Testing (IAST) tool that passively instruments Java applications to detect vulnerabilities and…

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and…

PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…

C++ library for detecting cross-site scripting (XSS) vulnerabilities in URLs through pattern analysis, with server modules and command-line tools for…

Security testing framework for repositories and source code

Exploit code for CVE-2021-2394, a Java vulnerability, providing proof-of-concept for security testing and research.

Demo environment for CVE-2022-22980 (Spring Data MongoDB SpEL injection RCE) with vulnerable application code for security testing and education.

Proof-of-concept emulation and analysis of CVE-2025-1094, a critical PostgreSQL SQL injection vulnerability. Includes Docker-based lab setup, exploit…

🔐 CVE-2026-57821 - Apache Fineract SQL Injection Toolkit 📚 Two Python scripts for authorized security testing: verifier.py (safe detection, no…

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

Demonstration of CVE-2022-22947 exploit for Spring Cloud Gateway, providing a proof-of-concept for security testing and vulnerability analysis.

Proof-of-concept exploit for CVE-2023-29007, a Git arbitrary configuration injection vulnerability. Demonstrates exploitation on Windows systems for…

Pre-authentication remote code execution exploit for FUEL CMS 1.4.1 (CVE-2018-16763). Python-based proof-of-concept for security testing and…

Proof-of-concept exploit for CVE-2026-44788, demonstrating vulnerability exploitation in C# for security testing and validation.

PHP object injection exploit for CVE-2026-49105 targeting WP Zendesk plugin. Provides proof-of-concept code for security testing and vulnerability…

Proof-of-concept exploit for CVE-2023-27363, demonstrating a specific vulnerability with automated exploitation logic for security testing and…

Proof-of-concept exploit for CVE-2024-24725, demonstrating a web application vulnerability with PHP-based exploitation code for security testing and…