
log4j2-CVE-2021-45046
Sample Spring Boot web application vulnerable to Log4j2 CVE-2021-45046, demonstrating JNDI injection and infinite loop exploitation for educational…

Sample Spring Boot web application vulnerable to Log4j2 CVE-2021-45046, demonstrating JNDI injection and infinite loop exploitation for educational…

Exploit script for CVE-2022-29469, a web application vulnerability, providing automated exploitation for penetration testing and security assessment.

PoC and Advisory for CVE-2025-70849: Unauthenticated Stored XSS in Podinfo /store endpoint.

CVE-2025-70849: Stored XSS in Podinfo

Fixed exploit for CVE-2022-46169 targeting a web application vulnerability, enabling authenticated remote code execution for penetration testing and…

Deliberately vulnerable web application portal with a containerized backend, designed for practicing exploitation of CVE-2021-44228 and container…

Vulnerable Spring Boot web application demonstrating Log4j2 JNDI injection (CVE-2021-44228) with exploitation steps and mitigation guidance for…

Sets up a vulnerable Django web application and provides a PDF detailing exploitation of CVE-2025-64459 for security training and lab practice.

Python exploit for CVE-2019-9053 targeting a web application vulnerability. Based on the original Exploit-DB submission, designed for penetration…

Sample Spring Boot web application vulnerable to Log4j2 CVE-2021-45105 with documented exploitation steps and mitigation guidance for security…

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Security research tool for detecting and testing CVE-2025-64446 (FortiWeb Path Traversal RCE vulnerability)

Security research on Fortinet FortiWeb vulnerabilities (CVE-2025-64446, CVE-2025-58034)

Educational Joomla SQL injection exploit (CVE-2017-8917) demonstrating web application vulnerability exploitation for academic cybersecurity training.

CVE-2025-26054

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

Test application for CVE-2025-29927, designed for security study groups to demonstrate and verify the web vulnerability in a controlled environment.

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…