
payloads
Git All the Payloads! A collection of web attack payloads.

Git All the Payloads! A collection of web attack payloads.

A vulnerable version of Rails that follows the OWASP Top 10

Automated JWT security testing tool that exploits known CVEs, tampers with payloads, performs JKU/X5U injection, key confusion attacks, and verifies…

Curated collection of cybersecurity learning resources, CTF writeups, research papers, and practical labs for hands-on skill development across web…

Detailed writeup of CVE-2021-41773 Apache path traversal and RCE exploitation, with step-by-step commands and root cause analysis from a TryHackMe…

Local Linux enumeration script that identifies privilege escalation vectors including misconfigurations, world-writable files, clear-text passwords,…

A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me

Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

AI security agent that runs in your terminal, orchestrating local tools, runbooks, and agents for authorized AppSec, pentest, OSINT, and CTF…

OpenType font that disassembles Z80 instructions

Go package that aids in binary analysis and exploitation

A plugin that provides resources for beginners to learn reverse engineering using Binary Ninja. It automatically installs several other plugins, and…

This repository contains a number of insecure self-hosted applications that allows interested security engineers to test vulnerabilities found by…

This repository contains a proof of concept (POC) and an exploit script for CVE-2025-29927, a critical vulnerability in Next.js that allows attackers…

A small go harness that uses Ollama to orchestrate LLMs in a restricted process flow

Python automation script that reproduces CVE-2022-22963, a critical SpEL injection in Spring Cloud Function, enabling reverse shell in authorized lab…

React2Shell, CVE-2025-55182, RCE Vulnerability: A critical breakdown of the unsafe deserialization flaw in React Server Components that enables…

CVE-2025-6934 is a critical vulnerability in the WordPress Opal Estate Pro plugin (<= 1.7.5) that allows unauthenticated attackers to create new…