
DEFCON-CICD-pipelines-workshop
Hands-on CI/CD pipeline security workshop with Terraform lab, AWS exploitation, Kubernetes escape, and artifact backdooring exercises for offensive…

Hands-on CI/CD pipeline security workshop with Terraform lab, AWS exploitation, Kubernetes escape, and artifact backdooring exercises for offensive…

Repository contains psexec, which will help to exploit the forgotten pipe

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

CVE-2020-0796 Flaw Mitigation - Active Directory Administrative Templates

Script - Workaround instructions to address CVE-2021-44228 in vCenter Server

The CVE-2024-46982 is cache poisoning of next_js some site have API to load their image

This repository contains potential security patches for the Magento APSB22-48 and CVE-2022-35698 security vulnerability

HAProxy-CVE-2023-45539-PoC

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses MultipartFile.transferTo() to…

Proof-of-concept exploit for CVE-2022-45265 targeting Sourcecodester Sanitization Management System 1.0 via unauthenticated user modification through…

reproducing an old istio bug

A registry-based workaround can be used to help protect an affected Windows server, and it can be implemented without requiring an administrator to…

How to "recover" a CloudPanel server affected by the CVE-2024-44765 vulnerability

Proof-of-concept for CVE-2021-27187: cleartext credential storage in FX Aggregator terminal client login.sav file, enabling local credential theft…

Java agent that transforms a vulnerable class to block exploitation of CVE-2024-43044 in Jenkins controllers, with optional forced shutdown on…

general purpose workaround for the log4j CVE-2021-44228 vulnerability

Apache CloudStack vulnerability allows unauthorized access to annotations on certain resources.