
RRAS-VULNERABILITY-CVE-2026-25172-CVE-2026-25173-CVE-2026--26111
Isolated lab environment to simulate and study integer overflow vulnerabilities (CVE-2026-25172, CVE-2026-25173, CVE-2026-26111) in Windows RRAS…

Isolated lab environment to simulate and study integer overflow vulnerabilities (CVE-2026-25172, CVE-2026-25173, CVE-2026-26111) in Windows RRAS…

Security research tool for detecting and testing CVE-2025-12735 (expr-eval RCE vulnerability)

Educational lab environment demonstrating SAMLStorm (CVE-2025-29775) vulnerability in xml-crypto library. Includes vulnerable SAML service provider,…

Scanner and exploit tool for CVE-2024-4577, a PHP CGI argument injection vulnerability enabling remote code execution on Windows systems. Includes…

Security research tool for detecting and testing CVE-2025-12735 (expr-eval RCE vulnerability)

A tool for vulnerability detection and exploitation tool for CVE-2024-31982

Command-line scanner for detecting and exploiting CVE-2025-55182 (React Server Components RCE) in Next.js applications. Supports custom command…

Python-based DDoS tool for educational network stress testing. Supports multi-threaded attacks against IP/URL targets with configurable worker count…

Proof-of-concept exploit for CVE-2026-42945 (NGINX Rift) with multi-mode RCE, blind verification, reverse shell, and batch scanning capabilities for…

Command-line scanner for detecting and exploiting CVE-2025-55182 (RCE) in Next.js React Server Components. Supports batch scanning from domain lists…

Bash-based scanner for detecting and exploiting CVE-2025-55182 (React Server Components RCE) in Next.js applications. Supports custom command…

a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC). It also includes a realistic "Lab Environment" to safely test…

CVE-2024-50603: Aviatrix Controller Unauthenticated Command Injection

Proof-of-Concept of the CVE-2025-9491 using invisible characters in the arguments of a Windows shortcut file (.lnk)

CVE-2024-34102: Unauthenticated Magento XXE

CVE-2024-27292 : Docassemble V1.4.96 Unauthenticated Path Traversal

CVE-2024-5009 : WhatsUp Gold SetAdminPassword Privilege Escalation

Cisco Unified Communications Manager (Unified CM) deployments affected by CVE-2026-20230.