
CVE-2021-44228
DO NOT USE FOR ANYTHING REAL. Simple springboot sample app with vulnerability CVE-2021-44228 aka "Log4Shell"

DO NOT USE FOR ANYTHING REAL. Simple springboot sample app with vulnerability CVE-2021-44228 aka "Log4Shell"

CMS Made Simple < 2.2.10 - SQL Injection . Actual working version

Python 3 exploit for CVE-2019-9053, an unauthenticated time-based blind SQL injection in CMS Made Simple < 2.2.10, extracting admin credentials and…

Demonstrates exploitation and mitigation of CVE-2024-10924, an authentication bypass in WordPress Really Simple Security, with automated Python…

This is a modified version of the time-based SQL injection exploit for CMS Made Simple <= 2.2.9. The exploit was originally created by Daniele Scanu…

Unauthenticated remote code execution exploit for Simple Image Gallery 1.0, with a detailed write-up and ExploitDB reference.

A short and sweet simple exploit script for the CVE-2012-2982 Authenticated RCE vulnerability in the /file/show.cgi/bin endpoint.

A simple simulation of the infamous CVE-2021-44228 issue.

Step-by-step CTF walkthrough demonstrating CVE-2019-9053 SQL injection exploitation and GTFOBins-based privilege escalation on a CMS Made Simple…

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

PoC for CVE-2018-15133 (Laravel unserialize vulnerability)

Spring Boot Log4j - CVE-2021-44228 Docker Lab

Adobe Magento SessionReaper LFI Vulnerability

log4j2 Log4Shell CVE-2021-44228 proof of concept

CVE-2018-12386 - Firefox Sandboxed RCE Exploit for Linux (Firefox <v62.0.3)

Apache Struts CVE-2017-5638 RCE exploitation

Deliberately vulnerable Next.js application designed for practicing exploitation of CVE-2025-29927, with a tutorial video for guided learning.

Proof-of-concept exploit for CVE-2026-55168 demonstrating authenticated arbitrary file write via symlink planting during backup restore in Runtipi.