
XSStrike
Advanced XSS detection suite with context-aware payload generation, multi-threaded crawling, WAF evasion, and DOM scanning for automated web security…

Advanced XSS detection suite with context-aware payload generation, multi-threaded crawling, WAF evasion, and DOM scanning for automated web security…

Intentionally vulnerable Next.js lab for CVE-2025-55182 exploitation research. Docker-packaged environment for practicing web application security…

Micro lab for CVE-2021-44228 (Log4Shell) with automated multi-target exploitation, runtime payload generation, and adjustable bypasses for security…

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

Web technology identification scanner with 1800+ plugins for detecting CMS, servers, JS libraries, and embedded devices. Supports stealthy to…

Perl-based web server scanner that performs comprehensive vulnerability checks, CGI scanning, and server fingerprinting with customizable plugins and…

Reproducer for CVE-2026-49042: demonstrates prompt injection in Apache Camel's langchain4j-tools leading to RCE via unfiltered Exchange headers.…

Multi-architecture Docker toolkit for penetration testing with preconfigured tools for web, network, mobile, API, OSINT, and forensics. Features…

Proof-of-concept exploit for CVE-2021-40438 (Apache mod_proxy SSRF) with Docker-based vulnerable environment for testing and validation.

PoC exploit for CVE-2025-32375 targeting BentoML 1.4.7, with a Docker-based vulnerable environment for testing and verification of the remote code…

Hands-on lab environment for testing Apache Tomcat unauthenticated RCE (CVE-2025-24813) with Docker setup and step-by-step exploitation guide.

Dockerized proof-of-concept exploit for CVE-2018-11776 (Apache Struts2) with a Go-based command execution payload for penetration testing and…

Dockerized exploit for OwnCloud CVE-2023-49103, providing a ready-to-use container for testing and validating the vulnerability in web application…

Isolated research lab and proof-of-concept for validating a SharePoint deserialization vulnerability (CVE-2025-53770) with a Python exploit driver,…

A containerized testing environment for CVE-2025-55182, a critical (10.0 CVSS) Remote Code Execution vulnerability in React Server Components.

Educational proof-of-concept exploit for CVE-2025-55182 targeting a React application, with Docker Compose environment for local testing and security…

CVE-2022-0543 - Redis RCE Vulnerability home lab for Red Teaming, Penetration Testing Training with just one DOCKER

Docker-based exploit for CVE-2024-835 vulnerability with automated deployment via docker-compose for penetration testing and security assessment.