
bunkerweb
🛡️ Open-source and cloud-native Web Application Firewall (WAF)

🛡️ Open-source and cloud-native Web Application Firewall (WAF)


Python script to generate a malicious MP4 file and start a CherryPy web server hosting a simple HTML page with the embedded file. Exploits another…

CVE-2022-29221 Proof of Concept Code - Smarty RCE

Exploit script for Apache Struts2 REST Plugin XStream RCE (CVE-2017-9805)

Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution…

Hooked browser communication over MQTT

Remote Code execution in CentOS web panel

Exploit script for Apache Struts2 REST Plugin XStream RCE (CVE-2017-9805)

Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c

CVE-2014-8731 - PHPMemcachedAdmin RCE - Proof of Concept

POC For CVE-2020-7693 (Testing on Version [email protected])

An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in…


The flaw allows an attacker to execute arbitrary system commands on the server hosting the Pterodactyl Panel without any prior authentication.