
java-vulnerable
EXPOSURE demo target: Tomcat (CVE-2016-0714) + Apache Rave (CVE-2013-1814) + Java filter-padding deps

EXPOSURE demo target: Tomcat (CVE-2016-0714) + Apache Rave (CVE-2013-1814) + Java filter-padding deps

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses MultipartFile.transferTo() to…

HAProxy-CVE-2023-45539-PoC

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

Vajra is a UI-based tool with multiple techniques for attacking and enumerating in the target's Azure and AWS environment. It features an intuitive…

Apache CloudStack vulnerability allows unauthorized access to annotations on certain resources.

How to "recover" a CloudPanel server affected by the CVE-2024-44765 vulnerability

SimplCommerce is affected by a Broken Access Control vulnerability in the review system, allowing unauthorized users to post reviews for products…

The CVE-2024-46982 is cache poisoning of next_js some site have API to load their image

Repository contains psexec, which will help to exploit the forgotten pipe

Java agent that transforms a vulnerable class to block exploitation of CVE-2024-43044 in Jenkins controllers, with optional forced shutdown on…

This repository contains potential security patches for the Magento APSB22-48 and CVE-2022-35698 security vulnerability

reproducing an old istio bug

Proof-of-concept exploit for CVE-2022-45265 targeting Sourcecodester Sanitization Management System 1.0 via unauthenticated user modification through…

Hands-on CI/CD pipeline security workshop with Terraform lab, AWS exploitation, Kubernetes escape, and artifact backdooring exercises for offensive…

Script - Workaround instructions to address CVE-2021-44228 in vCenter Server

general purpose workaround for the log4j CVE-2021-44228 vulnerability