
CVE-2023-26692
ZCBS/ZBBS/ZPBS v4.14k - Reflected XSS

ZCBS/ZBBS/ZPBS v4.14k - Reflected XSS

Proof-of-Concept exploit of CVE-2018-19131: Squid Proxy XSS via X.509 Certificate

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

w3af: web application attack and audit framework, the open source web vulnerability scanner.

Vulmap 是一款 web 漏洞扫描和验证工具, 可对 webapps 进行漏洞扫描, 并且具备漏洞验证功能

An NFC research toolkit application for Android

The Offensive Manual Web Application Penetration Testing Framework.

Automatic SSTI detection tool with interactive interface

SQL Injection Exploitation Tool

Python script to inject existing Android applications with a Meterpreter payload.

Full exploit chain (CVE-2019-11708 & CVE-2019-9810) against Firefox on Windows 64-bit.

A PoC application demonstrating the power of an Android kernel arbitrary R/W.

An exploit for Apache Struts CVE-2017-5638

A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.


Remote Code Execution Exploit for Citrix Application Delivery Controller and Citrix Gateway [ CVE-2019-19781 ]

An interactive multi-user web JS shell