
RevCAT
OpenCATS <= 0.9.4 RCE (CVE-2021-41560)

OpenCATS <= 0.9.4 RCE (CVE-2021-41560)

Proof-of-concept exploit for CVE-2019-5736, a Docker container escape vulnerability, demonstrating how to overwrite the host runc binary to gain…

Python simulation of CVE-2026-22012, showing how a missing Final-Unit-Indication in Diameter Credit-Control allows unlimited quota and service bypass…

Wordpress Plugin Simple Job Board 2.9.3 LFI Vulnerability (CVE-2020-35749) proof of concept exploit

This exploit is remote code execution vulnerability in Ruby-on-Rails when using render on user-supplied data

Sketchup MAC Pict Material Palette Stack Corruption

BookingPress < 1.0.11 - Unauthenticated SQL Injection


A vulnerable version of Rails that follows the OWASP Top 10

Demonstrates that Claude Opus fails to identify CVE-2023-0266, hallucinating lock acquisitions and producing false positives, with reproducible demos…

Ruby on Rails test case demonstrating CVE-2019-5418 file content disclosure via path traversal in Accept header, with PoC and reproduction steps.

Demo app showing how the Rails CVE-2013-5664 vulnerability works.

A Stored Cross-Site Scripting (XSS) vulnerability exists in Issabel-PBX version 4.0.0-6. The application fails to properly sanitize and encode…

Demonstration of CVE-2020-8165 Rails deserialization RCE exploit with realistic Shouter app, payload generation in Ruby, and Redis cache poisoning.

Educational demonstration of CVE-2017-17917 SQL injection in Rails, with step-by-step replication and secure coding mitigation using parameterized…

Educational demonstration of CVE-2007-4559 Python tarfile symlink attack with a script showing why os.path.realpath() fails to prevent extraction…

Docker-based sandbox to reproduce and test CVE-2019-5418 Ruby on Rails path traversal vulnerability via crafted Accept headers.

Silly Rails App to demonstrate vuln CVE-2013-0156