
dockerCVE-2024-835
Docker-based exploit for CVE-2024-835 vulnerability with automated deployment via docker-compose for penetration testing and security assessment.

Docker-based exploit for CVE-2024-835 vulnerability with automated deployment via docker-compose for penetration testing and security assessment.

Exploit PoC for CVE-2026-56848, a Node.js HTTP/2 heap-use-after-free that allows remote unauthenticated DoS. Includes raw-socket trigger, ASan build…

Automates DLL hijacking and DLL proxying research on Windows binaries by analyzing PE imports, generating proxy DLLs, and producing proof-of-concept…

Proof-of-concept reproducing CVE-2026-48206 header injection in Apache Camel camel-jira, demonstrating authorization bypass via user-controlled…

Reproducer for CVE-2026-49042: demonstrates prompt injection in Apache Camel's langchain4j-tools leading to RCE via unfiltered Exchange headers.…

Reproducer for CVE-2026-49099 demonstrating SOQL injection via HTTP header override in Apache Camel camel-salesforce, with mock Salesforce backend…

PoC reproducer for CVE-2026-53913 demonstrating a fail-open authentication bypass in Apache Camel's camel-keycloak, leading to unauthenticated RCE…

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

Docker-based Shellshock (CVE-2014-6271) exploit environment with ready-to-use attack scripts for CGI, SSH, and DHCP vectors. Includes vulnerable Bash…

Java XML serialization library with a focus on CVE-2021-21345 exploit analysis and deserialization vulnerability testing for web applications.

Java agent that intercepts CVE-2022-42889 (Text4Shell) exploitation attempts via JVM startup parameters or JPS PID injection, with runtime detection…

AWS Organization-wide detection toolkit for CVE-2025-55182 & CVE-2025-66478 (React Server Components / Next.js RCE vulnerabilities)

Dockerized exploit for OwnCloud CVE-2023-49103, providing a ready-to-use container for testing and validating the vulnerability in web application…

Micro lab for CVE-2021-44228 (Log4Shell) with automated multi-target exploitation, runtime payload generation, and adjustable bypasses for security…

Reproducer for CVE-2026-46726 demonstrating WebSocket header injection in Apache Camel camel-vertx-websocket enabling SSRF and property-placeholder…

Reproducer for CVE-2026-46592 demonstrating SOAP operation redirection via operationName header injection in Apache Camel camel-cxf, enabling…

Reproducer for CVE-2026-46456: Apache Camel camel-aws2-sqs inbound message-attribute header injection enabling downstream producer steering and RCE…

Reproducer for CVE-2026-46455 demonstrating Apache Camel camel-keycloak authentication bypass via missing TokenVerifier.IS_ACTIVE check, allowing…