
ecapture
Capturing SSL/TLS plaintext without a CA certificate using eBPF. Supported on Linux/Android kernels for amd64/arm64.

Capturing SSL/TLS plaintext without a CA certificate using eBPF. Supported on Linux/Android kernels for amd64/arm64.

Proof-of-concept exploit demo for CVE-2025-66478 using Node.js

a dart package to analyze CVE-2025-55182 react2shell

Jackson Rce For CVE-2019-12384

Burp Suite extension to generate Intruder payloads using Radamsa

CVE-2019-14540 Exploit

Working proof of concept for NextJS RCE to establish a reverse shell. [React2Shell]

CVE-2025-24813利用工具

Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known…

Educational cyber range for CVE-2026-59827 (Metabase H2 unsafe deserialization / CWE-502). Isolated Docker lab — training only, not for attacking…

PoC for CVE-2026-42945 (nginx Rift) — heap buffer overflow in ngx_http_rewrite_module. Includes detect/probe/exploit modes, dual-fixture Docker lab,…

Spring4Shell (CVE-2022-22965) 漏洞環境搭建與 CTF 題目

SnakeYAML CVE-2022-1471 exploit payload for demo

Intentionally vulnerable Next.js corporate landing page demonstrating CVE-2025-55182, a JSON injection leading to RCE/SSRF via unsafe deserialization…

POC for CVE-2025-24813 using Spring-Boot

Proof-of-concept exploit for CVE-2021-44228 (Log4Shell) targeting Java applications via JNDI injection for remote code execution.