
CVE-2024-22243
Example exploitable scenarios for CVE-2024-22243 affecting the Spring framework (open redirect & SSRF).

Example exploitable scenarios for CVE-2024-22243 affecting the Spring framework (open redirect & SSRF).

Reproducer for CVE-2026-47323: Apache Camel CXF/Knative HeaderFilterStrategy missing inbound filtering, enabling Camel control-header injection (RCE…

Proof-of-concept exploit for CVE-2026-5029, delivering unauthenticated remote code execution via the run-code MCP tool on exposed HTTP endpoints.…

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…

🔍 Recon notes organizer for bug bounty hunters and CTF players — subdomains, ports, endpoints, vulns, all in one place.

A little tool to play with Azure Identity - Azure and Entra ID lab creation tool. Blog: https://medium.com/@iknowjason/sentinel-for-purple-teaming-1…

Reproducer for CVE-2026-48206: Apache Camel camel-jira IssueKey (and other non-Camel-prefixed) header injection driving arbitrary JIRA issue…

FortiGate CVE-2022-40684 assessment tool for user enumeration, configuration dump, and lab testing.

Curated guide to zero-data-retention configurations for LLM APIs. Covers provider-specific ZDR endpoints, threat models, compliance mappings, and…

CVE-2021-44228 Log4j Summary

Reproduction project for CVE-2026-16723, a critical RCE in fastjson 1.2.68-1.2.83. Demonstrates AutoType bypass, JNDI injection, and TemplatesImpl…

Deliberately vulnerable Apache Solr application (CVE-2021-44228) for practicing Log4Shell exploitation via User-Agent, POST, and admin endpoints.…

Rewe API reverse engineering in Go

Proof-of-concept exploit for unauthenticated remote code execution in MaxSite CMS <= 109.1 via MarkItUp editor AJAX endpoints, with detection and…

Proof-of-concept exploit for CVE-2023-25690 HTTP Request Smuggling in Apache mod_proxy. Includes lab environment with Docker, BurpSuite walkthrough,…

Docker-based test environment for validating CVE-2024-23113 Nuclei templates against simulated vulnerable FortiOS instances, supporting multiple…

Documentation of CVE-2026-26418, a missing authentication and authorization vulnerability in TCS Cognix Recon Client v3.0 Web API, including affected…

Proof-of-concept exploit for CVE-2026-32136: unauthenticated authentication bypass in AdGuard Home via HTTP/2 cleartext (h2c) upgrade. Demonstrates…