
WSGoat
The vulnerable application that will teach you how to hack WebSockets

The vulnerable application that will teach you how to hack WebSockets

Educational proof-of-concept demonstrating how to embed a Meterpreter backdoor into a PDF file exploiting CVE-2010-1240, with step-by-step Metasploit…

CVE-2025-54100 (CVSS 7.8 High) is a command injection vulnerability in the Invoke-WebRequest cmdlet of Windows PowerShell 5.1. It arises from…

Exploit created by: R4v3nBl4ck end Pacman

Demo project how to bypass the disable_functions security control of PHP on Linux

Demonstrates exploitation of CVE-2017-8046 in a Spring Boot application, including a SpEL injection payload and dependency-check verification for…

Proof-of-concept exploit for CVE-2024-2961, leveraging iconv encoding flaws and PHP filter chains to read arbitrary files from vulnerable servers via…

Python exploit for CVE-2014-6271 (ShellShock) enabling remote code execution via crafted environment variables in GNU Bash, targeting web servers and…

Detailed technical write-up and proof-of-concept exploit for CVE-2023-33733, a remote code execution vulnerability in the Reportlab Python library…

Proof of Concept of apache log4j LDAP lookup vulnerability. CVE-2021-44228

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Primefaces <= 5.2.21, 5.3.8 or 6.0 - Remote Code Execution Exploit

Burp Plugin to Bypass WAFs through the insertion of Junk Data

Tests your WAF with +160 payloads

Intentionally vulnerable Python lab demonstrating unsafe YAML deserialization leading to code execution, with three difficulty levels, exploit…

Next.js and the corrupt middleware...TRY TO HACK IT..!

Buildpack providing a workaround for CVE-2021-44228 (Log4j RCE exploit)

exp for https://research.checkpoint.com/extracting-code-execution-from-winrar