
waf-community-bypasses
Curated CSV collection of community-sourced Web Application Firewall bypass payloads for testing and validating WAF protections.

Curated CSV collection of community-sourced Web Application Firewall bypass payloads for testing and validating WAF protections.

The script exploits Mailcow vulnerabilities via XSS and RCE, emphasizing the need for robust security measures and responsible usage to enhance web…

Web Application Exploit Development

Proof-of-concept exploit for CVE-2018-14667 with a Windows calc payload, demonstrating remote code execution in a web application context.

Proof-of-concept web application demonstrating CVE-2022-36067, a vm2 sandbox escape, enabling remote code execution by uploading exploit code to a…

Proof-of-concept Python script demonstrating authenticated remote code execution in NETGEAR ProSAFE Network Management System via vulnerable Apache…

Proof-of-concept exploit for CVE-2019-11043, a PHP-FPM underflow vulnerability, built on the pocsuite framework for automated web application…

PoC exploit for CVE-2020-9484, and a vulnerable web application for its demonstration

Educational demonstration of CVE-2017-5123 kernel exploit, ICMP-based rootkit command-and-control, and OS command injection vulnerable web…

Proof-of-concept exploit for CVE-2024-2054, demonstrating insecure deserialization RCE in Artica-Proxy administrative web application. Includes…

React Shell & Next.js RSC Exploit Tool (CVE-2025-55182)

Server-Side Template Injection Exploit

Security research tool for detecting and testing CVE-2025-64446 (FortiWeb Path Traversal RCE vulnerability)

Detailed analysis and proof-of-concept exploit for CVE-2017-9822, an XXE/insecure deserialization vulnerability in DotNetNuke CMS leading to remote…

Proof of concept exploit for CVE-2019-10068.

Local file inclusion exploitation tool

Weblogic com.tangosol.util.extractor.ReflectionExtractor RCE
