
spring-boot-cve-2022-22965
Showcase of overridding the Spring Framework version in older Spring Boot versions

Showcase of overridding the Spring Framework version in older Spring Boot versions

PoC and fix for CVE-2024-38828: Spring Framework DoS via Content-Length manipulation in ByteArrayHttpMessageConverter. Includes load testing,…

Curated Java web framework vulnerability (CVE-2016-5394) for Apache Sling, designed for security testing, exploitation practice, and vulnerability…

(CVE-2017-9841) PHPUnit_eval-stdin_php Remote Code Execution

Test & Analyze the CVE-2025-55182 vulnerability within Next.js Server Actions

Exploit for Apache Struts CVE-2017-9805, a remote code execution vulnerability in the REST plugin. Enables penetration testing and security…

Proof-of-concept exploit for CVE-2022-27772 targeting Grails 3.3 framework's custom TomcatEmbeddedServletContainerFactory, demonstrating insecure…


Spring messaging STOMP protocol RCE

WordPress wp2shell pre-auth RCE exploit kit (CVE-2026-63030 + CVE-2026-60137)

Docker-based lab demonstrating CVE-2018-3760 path traversal in Ruby on Rails Sprockets, with POC and environment setup for security testing and…

Proof-of-concept exploit for CVE-2025-69515 demonstrating static GPS spoofing on JXL 9-inch Android infotainment units via SDR-based signal…

Static Go proof-of-concept for CVE-2026-31431, leveraging Linux AF_ALG and splice(2) to trigger the vulnerability. Provides prebuilt binaries for…

Pure Rust proof-of-concept for CVE-2026-31431, targeting Linux x86_64 kernels with AF_ALG AEAD support. Static musl build, no runtime dependencies,…

Minimal 587-byte static ELF exploit for CVE-2026-31431, achieving local privilege escalation via AF_ALG splice page cache corruption. No libc or…