
WSGoat
The vulnerable application that will teach you how to hack WebSockets

The vulnerable application that will teach you how to hack WebSockets

analysis of the sudo buffer overflow affect sudo version <1.8.26 and how to use GCC to compile publicly availible exploits

A security auditing toolkit for CVE-2026-31431 vulnerability research

Unauthenticated RCE scanner for FortiSandbox CVE-2026-39808 with canary-based verification, command execution, and pipeline integration for mass…

Proof-of-concept exploit for CVE-2021-34600, demonstrating a key generation vulnerability in Telenot access control systems using Proxmark3 RFID…

Proof-of-concept exploit for CVE-2021-3864, a privilege escalation vulnerability in logrotate, demonstrating core file generation to achieve root…

Analyzes CVE-2021-42948, a session token exposure vulnerability in HotelDruid, demonstrating how GET parameters leak session IDs and enable session…

Proof-of-concept for an authentication bypass in PerfexCRM prior to 3.3.1, demonstrating how empty credentials can grant unauthorized admin access.

A simple demo application that shows how to reproduce the Ivanti EPMM pre-auth RCE vulnerability (CVE-2026-1281 / CVE-2026-1340) for educational and…

Python exploit script for CVE-2026-23744 that delivers a reverse shell to a specified target URL, requiring a netcat listener for command-and-control.

Vulnerability triage with provenance. Resolves CVEs from locally built corpora (NVD/KEV/EPSS, ExploitDB, nmap script.db) and emits verification…

C# Tool to interact with MS Exchange based on MS docs

Tips on how to write exploit scripts (faster!)

A list of edge cases that occur in bug bounty programs, conversations on how they should be handled. The goal is to standardise the way that specific…

Some scripts to abuse kerberos using Powershell

how to look for Leaked Credentials !

Burp Plugin to Bypass WAFs through the insertion of Junk Data
