
zenbuster
Multi-threaded URL enumeration/content-discovery tool in Python.

Multi-threaded URL enumeration/content-discovery tool in Python.

Docker-based lab for exploiting CVE-2026-25993, a second-order SQL injection in EverShop. Deploy, enumerate, and dump the database via crafted…

Cross-site scripting labs for web application security enthusiasts

Self-contained Docker lab demonstrating CVE-2023-24329, a Python urllib parser differential that bypasses URL scheme and host filters, with…

OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS

PoC for CVE-2025-50365: a CSRF flaw in PHPGurukul Maid Hiring Management System allowing deletion of hiring categories via a crafted admin request.

Example exploitable scenarios for CVE-2024-22243 affecting the Spring framework (open redirect & SSRF).

CVE-2023-4220 — Unauthenticated file upload RCE in Chamilo LMS ≤ 1.11.24. OSCP-style and auto exploit.

Vuln lab: MainWP Dashboard <= 3.1.2 Unauthenticated Stored XSS