
XMGoat
Terraform-based Azure security lab with intentionally misconfigured environments for hands-on attack and compromise practice. Includes scenario flows…

Terraform-based Azure security lab with intentionally misconfigured environments for hands-on attack and compromise practice. Includes scenario flows…

Linux kernel local privilege escalation PoC for CVE-2026-43503 (DirtyClone). Exploits a cloned sk_buff flag loss to write into page-cache memory,…

A repository documenting security vulnerabilities discovered in Free and Open Source Software (FOSS) by VETTRIVEL U

CVE-2025-32433 PoC – SSH Protocol Python-based PoC for controlled lab testing of SSH message handling, channel operations, and pre-auth interactions.…

Technical study of the CVE-2025-68613 vulnerability in n8n, covering affected versions, laboratory exploration scenario, offensive and defensive…

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…

Run Radmin VPN on Linux via Wine — custom driver, TAP bridge, zero packet loss

A Burp Suite Extension for pentester and bug bounty hunters an to maintain checklist, map flows, write test cases and track vulnerabilities

FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).

A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities

Find vulnerabilities in AD Group Policy, but do it better than Grouper2 did.

Security toolkit for AI agents. Scan your machine for dangerous skills and MCP configs, monitor for supply chain attacks, test prompt injection…

Next Generation Firewall Audit and Bypass Tool

This project is now part of @mitmproxy.

PoC for CVE-2025-25198: automated Host header poisoning test for Mailcow - HTTPS listener, automatic cookie/CSRF handling, captures first reset link.

Proof-of-concept exploit for CVE-2026-48519, a pre-auth RCE in IBM Langflow <= 1.9.1 via the Shareable Playground /api/v1/build_public_tmp endpoint.

The vulnerability in Langflow 1.8.1 and earlier allows a remote, unauthenticated attacker to achieve arbitrary command execution on the host.

Reflected Cross-Site Scripting in Snipe-IT CSV Import Workflow