
juice-shop
Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

Educational standalone JavaScript implementation of the public exploit for CVE-2016-9079 (Firefox Use-After-Free), adapted from the original…

From deobfuscating code.js to root, CVE-2023-0386

This repository contains a proof of concept (POC) and an exploit script for CVE-2025-29927, a critical vulnerability in Next.js that allows attackers…

This repository contains a POC of CVE-2025-55182, a critical (CVSS score 10.0) pre-authentication remote code execution vulnerability affecting React…

CTF challenge focused on sandbox escape via source code review of a JavaScript execution environment, designed for hands-on vulnerability analysis…

A stored XSS in the project delete flow allows execution of attacker-controlled JavaScript in an administrator’s browser when the admin attempts to…

Proof-of-concept for a stored XSS vulnerability in Anchor CMS v0.12.7, demonstrating arbitrary JavaScript execution via the page description field.

A basic proof of concept of the CVE-2025-29927 vulnerability that allows to bypass the middleware scripts.

A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me

Serverside Template Injection (SSTI) RCE - THM challenge "whiterose"

Intentionally vulnerable web application for security training, CTF competitions, and testing security tools. Covers OWASP Top Ten vulnerabilities…