
KaiMonkey
Deliberately vulnerable Terraform infrastructure for learning cloud security misconfigurations and validating IaC scanner detection across AWS and…

Deliberately vulnerable Terraform infrastructure for learning cloud security misconfigurations and validating IaC scanner detection across AWS and…

Multi-threaded Go tool to detect nginx alias traversal vulnerabilities using heuristic and brute-force techniques for identifying vulnerable…

Static config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap…

Rapidly scan filesystems for Java programs potentially vulnerable to Log4Shell (CVE-2021-44228) or "that Log4j JNDI exploit" by inspecting the class…

A mitigation for CVE-2021-44228 (log4shell) that works by patching the vulnerability at runtime. (Works with any vulnerable java software, tested…

Nuclei template to detect Apache servers vulnerable to CVE-2024-38473

Fastest filesystem scanner for log4shell (CVE-2021-44228, CVE-2021-45046) and other vulnerable (CVE-2017-5645, CVE-2019-17571, CVE-2022-23305,…

A tool that checks if a TorchServe instance is vulnerable to CVE-2023-43654

Inspect all of your Heroku apps for vulnerable versions of the JSON gem

Proof-of-concept exploit for Kubernetes service-account token disclosure via hostPath mounts; includes vulnerable pod YAML and Python token-theft…

Exploit PoC and vulnerable admission webhook for CVE-2026-5556, demonstrating Kubernetes admission controller bypass via case-sensitive pod name…

Python PoC for CVE-2026-22007: NTP monlist amplification over IPv6, including a simulated vulnerable server and spoofed UDP reflection attack.

Permanent fix for Intel NUC WinRing0 vulnerable driver (CVE-2020-14979) reinstallation via Windows Update

Hands-on lab demonstrating Kubernetes container hardening by comparing default vs. security-enhanced deployments of a vulnerable note-taking…

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses MultipartFile.transferTo() to…

Demonstrates CVE-2023-34035 vulnerability in Spring Security with vulnerable and mitigated sample applications, teaching proper servlet mapping and…

A script to detect if xz is vulnerable - CVE-2024-3094

Automated detection of vulnerable domain configurations and subdomain takeover risks across cloud environments, with continuous monitoring and…