
CVE-2017-9798
Lightweight Python script to detect CVE-2017-9798 in shared hosting environments by scanning for vulnerable .htaccess files, exiting with code 1 if…

Lightweight Python script to detect CVE-2017-9798 in shared hosting environments by scanning for vulnerable .htaccess files, exiting with code 1 if…

Kubernetes Security Training Platform - focusing on security mitigation

Multi-cloud vulnerable-by-design deployment tool using Terraform to provision intentionally insecure cloud infrastructure for security training and…

Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings,…

Demonstrates CVE-2025-22235 Spring Boot authentication bypass via EndpointRequest.to() misconfiguration. Includes environment setup, reproduction…

Vajra is a UI-based tool with multiple techniques for attacking and enumerating in the target's Azure and AWS environment. It features an intuitive…

Local testing environment for Next.js middleware authorization bypass vulnerability (CVE-2025-29927). Demonstrates exploitation via crafted…

Proof-of-concept for authenticated remote code execution in Twenty CRM via unsandboxed serverless workflow functions, allowing arbitrary Node.js…

Checks a shared hosting environment for CVE-2017-9798

Starlette Host-Header URL Confusion Lab (X41-2026-002) - CVE-2026-48710

Docker-based lab for Apache CVE-2021-41773 path traversal and RCE exploitation with Python exploit script, demonstrating vulnerability analysis and…

Reproduces CVE-2025-0108 path confusion vulnerability in Nginx/Apache stacks. Includes a vulnerable PoC and a patched implementation demonstrating…

PoC for a security: potential path traversal with specific configs, if `mod_dirlisting` were enabled, which is not the default, this would result in…

CVE-2021-26084 patch as provided in "Confluence Security Advisory - 2021-08-25"

Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to…

Test tool for CVE-2024-26144 that checks if web servers and CDNs improperly cache HTTP responses containing Set-Cookie headers, revealing cache…

Web Vulnerability Scanner using Shell Script

TM4WEB Vulnerability - CVE-2022-35497