

CVE-2025-55182 React Server Components Remote Code Execution Exploit Lab


Academy LMS <= 5.10 CSRF

Test exploit of CVE-2021-44228

Log4Shell (CVE-2021-44228) docker lab

Dockerized Spring4Shell (CVE-2022-22965) proof-of-concept with Python exploit script and webshell deployment for educational vulnerability testing.

Reproduction of CVE-2025-29927 authorization bypass in Next.js middleware, with curl-based exploitation payloads for multiple versions.

Proof-of-concept for CVE-2025-492030: account takeover via session token validation bypass in SecureVPN API endpoint /api/v1/authenticate.

Proof-of-concept exploit for CVE-2024-22262 in Spring applications, with a Dev Container environment for hands-on vulnerability exploration and…

XSS vulnerability in Online Student Rate System1.0

OpenPLC 3 WebServer Authenticated Remote Code Execution.

MAL-011: Log4J Misconfiguration Allows Malicious JavaScript in Red Hat AMQ

Exploit for the Rails CVE-2019-5420

Proof-of-concept exploit for CVE-2020-5245, demonstrating expression language injection in Dropwizard REST endpoints via crafted HTTP parameters.

Proof-of-concept for CVE-2021-39378: SQL injection in openSIS 8.0 via the str parameter in NamesList.php, enabling database extraction and blind…

Proof Of Concept for the CVE-2016-10033 (PHPMailer)

Showcase of overridding the Spring Framework version in older Spring Boot versions