
cve-2025-13486-vuln-setup
Docker test environment for CVE-2025-13486 (ACF Extended RCE). For security research only.

Docker test environment for CVE-2025-13486 (ACF Extended RCE). For security research only.

Docker container for CVE-2019-6340 exploitation lab, part of the Cved vulnerable container management framework for practicing Drupal security…

Dockerized vulnerable Java application demonstrating CVE-2022-42889 (Text4Shell) remote code execution via Apache Commons Text string lookups, for…

Python proof-of-concept exploit for Apache Struts2 CVE-2018-11776 remote code execution vulnerability, with Docker container for testing against…

Proof-of-concept exploit for Apache HTTP Server path traversal vulnerability CVE-2021-41773, with Docker-based lab environment for testing.

Dockerized proof-of-concept for CVE-2017-9805, a remote code execution vulnerability in Apache Struts2 REST plugin, enabling automated exploitation…

Docker-based PoC for CVE-2018-11235 Git submodule RCE with ngrok tunneling for remote exploitation testing.

Proof-of-concept exploit for CVE-2024-22262 in Spring applications, with a Dev Container environment for hands-on vulnerability exploration and…

Python exploit script for CVE-2023-2982, packaged in a Docker container for automated deployment and testing against vulnerable targets.

Intentionally vulnerable Kubernetes cluster environment for hands-on security training. Includes 22+ scenarios covering container escape, RBAC…

Reproducer for CVE-2026-49099 demonstrating SOQL injection via HTTP header override in Apache Camel camel-salesforce, with mock Salesforce backend…

Differential testing framework for HTTP implementations

GUI Burp Plugin to ease discovering of security holes in web applications

Proof-of-concept reproducing CVE-2026-48206 header injection in Apache Camel camel-jira, demonstrating authorization bypass via user-controlled…

Reproducer for CVE-2026-46592 demonstrating SOAP operation redirection via operationName header injection in Apache Camel camel-cxf, enabling…

Java agent that intercepts CVE-2022-42889 (Text4Shell) exploitation attempts via JVM startup parameters or JPS PID injection, with runtime detection…

Instrumented fuzzer for PLC-based ICS control applications, targeting Codesys runtime on Wago controllers to uncover memory corruption and…

Coverage-guided fuzzer that uses taint tracking and scalar optimization to solve path constraints without symbolic execution, improving branch…