
CVE-2022-21449-vuln-test
Java-based tester for CVE-2022-21449 ECDSA signature verification vulnerability. Checks JVM for the Psychic Signatures bug and reports vulnerable or…

Java-based tester for CVE-2022-21449 ECDSA signature verification vulnerability. Checks JVM for the Psychic Signatures bug and reports vulnerable or…

Custom vulnerable VM (Ubuntu 14.04) designed for teaching multi-stage penetration testing. Features 10 interconnected challenges across Forensics,…

Exploit for CVE-2020-11998 targeting Apache ActiveMQ 5.15.12, enabling remote code execution via crafted messages to the vulnerable message broker.

Detects Windows and Linux systems with enabled Trusted Platform Modules (TPM) vulnerable to CVE-2017-15361. #nsacyber

Python Implementation of a .NET Padding Oracle Assessment Tool

Demonstrating that SSLVerifySignedServerKeyExchange() is trivially testable.

POC exploit of CVE-2021-3345, a vulnerability in libgcrypt version 1.9.0

CLI tool to scan codebases for quantum-vulnerable cryptography

Proof-of-concept exploit for CVE-2023-33242 demonstrating a bit extraction attack on the Lindell17 ECDSA protocol, enabling iterative private key…

Minimal proof-of-concept reproducer for CVE-2025-69419, a heap buffer overflow in OpenSSL's PKCS12_get_friendlyname() triggered by a crafted…

Educational laboratory for studying CVE-2014-0160 (Heartbleed) and framing inconsistencies in TLS heartbeat handling.

This is the Heratbleed bug (CVE-2014-0160) documentation I did for Advenced Cyber Attacks course.

repo showcasing generating "psychic signatures for java" implemented in a nodejs environment 😅

A generative test that would've caught CVE-2020-28052

Detailed walkthrough of exploiting CVE-2026-29000 in pac4j-jwt to bypass authentication, extract credentials from API settings, and escalate…

An app with really insecure crypto. To be used to see/test/exploit weak cryptographic implementations as well as to learn a little bit more about…