
CVE-2026-21852-PoC
Educational demo of three Claude Code vulnerabilities (hooks bypass, MCP injection, API key exfiltration) with attacker server, MITM proxy, and…

Educational demo of three Claude Code vulnerabilities (hooks bypass, MCP injection, API key exfiltration) with attacker server, MITM proxy, and…

CVE-2022-39197 RCE POC

Intentionally vulnerable Hospital Management System demonstrating SQL injection (CVE-2023-7172) with Docker setup and PoC for educational security…

Apache Struts2 CVE-2017-5638 (Safe Educational Demo)

Proof of Concept (POC) for the CVE-2025-25296 vulnerability affecting Label Studio versions prior to 1.16.0

Proof-of-concept demonstrating arbitrary command execution via malicious virtual environment activation scripts in PyCharm before 2020.3.4,…

Proof-of-concept exploit for CVE-2024-38820, demonstrating locale-dependent case conversion bypass of Spring Framework DataBinder disallowedFields…

HTTP Request Smuggling

CVE-2024-4367

Buildpack providing a workaround for CVE-2021-44228 (Log4j RCE exploit)

Offensive security tool for printer pentesting

Automatic UAC-Bypassing for custom payloads during privilege escalation testing

Exploit for CVE-2020-9283 based on Go

🌴Linux、macOS、Windows Kernel privilege escalation vulnerability collection, with compilation environment, demo GIF map, vulnerability details,…

Dahua Console, access internal debug console and/or other researched functions in Dahua devices. Feel free to contribute in this project.

Project Ares is a Proof of Concept (PoC) loader written in C/C++ based on the Transacted Hollowing technique

CVE-2022-22978 POC Project

This project for CVE-2019-18935