
SSRF-Testing
SSRF (Server Side Request Forgery) testing resources

SSRF (Server Side Request Forgery) testing resources

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

CVE-2026-22874 writeup: incomplete SSRF allow-list in Gitea webhook/migration (IPv6 transition and cloud metadata). Fixed in Gitea 1.26.3.

adaptive agents for dynamic web penetration testing

An analysis of CVE-2025-55182 and CVE-2025-66478 -- the vulnerabilities behind React2Shell. Tools, technical information, etc

PoC and writeup for CVE-2026-46394: OS command injection in HAXcms Git.php (CWE-78). Authorized security research only.


CVE-2018-12386 - Firefox Sandboxed RCE Exploit for Linux (Firefox <v62.0.3)

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata

CVE-2024-24576 PoC for Nim Lang

Artica Proxy before 4.30.000000 Community Edition allows Reflected Cross Site Scripting.

Awesome information for WebSockets security research

Cisco ASA Software and ASDM Security Research

CVE-2021-3262 - Blind SQL Injection in the editOEN parameter of TripSpark VEO Transportation / NovusEDU. Unauthenticated, internet-facing. Payloads,…

Walkthrough: ingress-nginx Configuration Injection via rewrite-target Annotation

NocoDB Shared-Base Links Could Invite Real Base Members and Survive Share Revocation

A critical SQL Injection vulnerability (CVE-2025-25964) discovered in the School Information Management System v1.0

eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's…