
vuln_spring_log4j2
Simple Vulnerable Spring Boot Application to Test the CVE-2021-44228

Simple Vulnerable Spring Boot Application to Test the CVE-2021-44228

Dockerized Go app for testing the CVE-2021-44228 vulnerability

CVE-2022-23305 Log4J JDBCAppender SQl injection POC

Analysis of CVE-2025-68613

🔓 Next.js Auth Bypass Demo - Educational application demonstrating CVE-2025-29927 middleware authentication bypass vulnerability . ⚠️ For…

Deliberately vulnerable Node.js web application containing 19+ security bugs (XSS, SSRF, Prototype Pollution, RCE) for hands-on penetration testing…

Intentionally vulnerable Kubernetes cluster environment for hands-on security training. Includes 22+ scenarios covering container escape, RBAC…

CVE-2026-44578: Next.js WebSocket Upgrade SSRF — pre-auth credential theft via localhost:80. Lab + exploit + audit.

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

PoC CVE-2023-27163, SSRF, request-baskets hasta v1.2.1


A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

This repository is for the Testing ASP.NET ViewState with YSoNet (YSoSerial.NET) workshop.

F5 BIG-IP iControl REST vulnerability RCE exploit with Java including a testing LAB

Making a lab and testing the CVE-2024-3116, a Remote Code Execution in pgadmin <=8.4

Proof of Concept Appliction for testing CVE-2022-42889

Proof-of-concept exploit for CVE-2026-52199: unauthenticated remote code execution via exposed ADB daemon on UZ801 4G LTE router. Includes…