
EverShop-Lab-CVE-2026-25993
Docker-based lab for exploiting CVE-2026-25993, a second-order SQL injection in EverShop. Deploy, enumerate, and dump the database via crafted…

Docker-based lab for exploiting CVE-2026-25993, a second-order SQL injection in EverShop. Deploy, enumerate, and dump the database via crafted…

Exploit for CVE-2025-2304

Struts2 S2-045(CVE-2017-5638)Exp with GUI

Generates obfuscated IP addresses and URLs using DWORD, octal, hex, IPv6-mapped, and fake-domain @ tricks for penetration testing, phishing…

Proof-of-concept and technical writeup for CVE-2025-59382, an unauthenticated password reset URL injection in QNAP NAS that enables a…

Proof of concept for CVE-2023-42284 in Tyk Gateway

Proof of concept for CVE-2023-42283 in Tyk Gateway

Cross-site scripting labs for web application security enthusiasts

Exploit for CVE-2024-46987

Python-based mass scanner for validating a specific WordPress AJAX behavior in authorized environments, supporting URL normalization, endpoint…

Educational proof-of-concept for CVE-2023-34468 affecting Apache NiFi. Demonstrates H2 JDBC URL abuse leading to authenticated RCE in vulnerable NiFi…

Proof-of-concept exploit for CVE-2023-24329, a Python urllib parsing flaw enabling URL confusion attacks. Includes a runnable script and references…

PhishCollector is a research framework for collecting, analysing, and tracking phishing sites.

An exploit for Apache Struts CVE-2018-11776

An exploit for Apache Struts CVE-2017-9805

An exploit for Apache Struts CVE-2017-9805

Proof-of-concept exploit for CVE-2024-9234, an unauthenticated arbitrary file upload vulnerability in GutenKit <= 2.1.0. Includes a Python script for…

Proof-of-concept demonstrating a CSRF vulnerability in a PHP-based Client Management System, with HTML exploit code and mitigation strategies for web…