
CVE-2022-46364---Apache-CXF-XOP-Include-LFI-PoC
Proof-of-concept exploit for CVE-2022-46364, a local file inclusion vulnerability in Apache CXF via crafted XOP Include elements in SOAP requests,…

Proof-of-concept exploit for CVE-2022-46364, a local file inclusion vulnerability in Apache CXF via crafted XOP Include elements in SOAP requests,…

HTB Snapped — Hard Linux machine writeup. CVE-2026-27944 (Nginx UI unauthenticated backup disclosure) chained with CVE-2026-3888 (snapd race…

Automatic Service Enumeration Script

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

一个轻量级浏览器抓包与安全分析扩展,在浏览器侧边栏中即可完成抓包、拦截、修改、重放、规则检测与AI辅助分析的完整工作流。(A lightweight browser extension for traffic capture and security analysis, enabling…

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

Hack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.

Interactive demo for CVE-2023-45857 (axios XSRF token bypass). Step-by-step guide to reproduce the vulnerability in a controlled dev container…