


Next.js and the corrupt middleware...TRY TO HACK IT..!

Proof-of-concept for CVE-2020-13777 (GnuTLS TLS 1.3 reconnect vulnerability). Parses pcap files to demonstrate the flaw for educational and technical…

A stored XSS in the project delete flow allows execution of attacker-controlled JavaScript in an administrator’s browser when the admin attempts to…

This is a modified version of the time-based SQL injection exploit for CMS Made Simple <= 2.2.9. The exploit was originally created by Daniele Scanu…

Hack this service to prove CVE-2022–29622 is valid

Created this exploit for the Hack The Box machine, Blurry.

Web application vulnerable to Python3 Flask SSTI (CVE-2019-8341)

CVE-2025-6934 is a critical vulnerability in the WordPress Opal Estate Pro plugin (<= 1.7.5) that allows unauthenticated attackers to create new…

Automated proof-of-concept exploit for CVE-2024-23334, a path traversal vulnerability in aiohttp, enabling remote directory traversal and…

Intentionally vulnerable PHP web app demonstrating SQL injection authentication bypass and unauthorized data disclosure modeled after CVE-2024-8465…


Some setup scripts for security research tools.