

patch-manager

PoC for CVE-2025-2011 - SQLi in Depicter plugin <= 3.6.1

CVE-2025-61246: SQL Injection vulnerability PoC in Online Shopping System PHP

Educational walkthrough for exploiting CVE-2025-68613, a critical RCE in n8n workflow automation. Covers expression injection, sandbox escape,…

Educational lab and PoC demonstrating CVE-2024-21413 Outlook Moniker Link attack to leak netNTLMv2 hashes via crafted HTML email.

Test & Analyze the CVE-2025-55182 vulnerability within Next.js Server Actions

CVE-2021-21980

This repository is to demonstrate and practice my forensic/vulnerability analysis skills by reproducing a web-related CVE in a safe environment.

Verified vulnerability journey for CVE-2025-8110 (Gogs) and CVE-2025-3248 (Langflow) — risk triage, exploitability verification, verified patches.

Expolit for CVE-2024-23334 (aiohttp >= 1.0.5> && <=3.9.1)

Proof-of-concept exploit for CVE-2021-44228 (Log4Shell) that automates LDAP and HTTP servers to deliver a reverse shell payload to a vulnerable Java…

Docker-compose to set up a test environment for exploiting CVE-2015-8562

Educational proof-of-concept exploit for CVE-2020-0796 (SMBGhost) demonstrating pre-auth RCE on Windows SMBv3. Includes step-by-step lab setup,…

Log4Shell Proof-Of-Concept derived from https://github.com/kozmer/log4j-shell-poc

Web application vulnerable to Python3 Flask SSTI (CVE-2019-8341)

Reproducible A/B lab + safe PoC for GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced)

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…