
PwnCity
Insecure TeamCity CI environment for hands-on penetration testing training: reconnaissance, credential theft, privilege escalation, and lateral…

Insecure TeamCity CI environment for hands-on penetration testing training: reconnaissance, credential theft, privilege escalation, and lateral…
CVE-2024-11972 in Hunk Companion <1.9.0 allows unauthenticated attackers to exploit insecure REST API endpoints and install vulnerable plugins,…

The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10

The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10

Demonstrates an IDOR vulnerability in TelegAI's chat API allowing unauthorized conversation tampering, leading to phishing and XSS-based account…

A collection of hacking / penetration testing resources to make you better!

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Collection of mobile reverse engineering challenges (UnCrackable Apps) from the OWASP MAS project for learning and practicing mobile app security…

Perl-based black-box vulnerability scanner for vBulletin CMS. Detects known vulnerabilities and misconfigurations to assist in penetration testing…

Python library built on Scapy for crafting, dissecting, and sending packets over SAP proprietary protocols (NI, Diag, RFC, HDB). Includes client,…

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Proof-of-concept exploit for CVE-2022-23808, a stored XSS vulnerability in phpMyAdmin 5.1.1 setup script, with payload and reproduction steps for…

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support

Automated path traversal and local file read exploit for SolarWinds Serv-U (CVE-2024-28995) with version detection, default and custom path testing,…

CVE-2024-27198 & CVE-2024-27199 PoC - RCE, Admin Account Creation, Enum Users, Server Information

CVE-2024-29895 PoC - Exploiting remote command execution in Cacti servers using the 1.3.X DEV branch builds

CVE-2026-60206 PoC: SAML authentication bypass exploit for Oracle WebLogic with multiple payload modes (XSW, unsigned, NameID) for penetration…