
railsgoat
A vulnerable version of Rails that follows the OWASP Top 10

A vulnerable version of Rails that follows the OWASP Top 10

A library for detecting known secrets across many web frameworks


Vulnerability scanner using Nmap for scanning and correlating found CPEs with CVEs.

PoC for CVE-2022-21971 "Windows Runtime Remote Code Execution Vulnerability"

The DCERPC only printerbug.py version

CVE-2019-5418 - File Content Disclosure on Ruby on Rails

RCE on Rails 5.2.2 using a path traversal (CVE-2019-5418) and a deserialization of Ruby objects (CVE-2019-5420)

CVE-2020-8163 - Remote code execution of user-provided local names in Rails

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

PoC for CVE-2022-21974 "Roaming Security Rights Management Services Remote Code Execution Vulnerability"

CVE-2017-11882 File Generator PoC

Testing POC for use cases

Forensic toolkit and agent skills for investigating Rails Active Storage/libvips CVE-2026-66066: detects crafted blob indicators, exposure windows,…

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

PoC for CVE-2026-66066 in Ruby on Rails