
CVE-2025-25198
Captures password reset tokens from Mailcow Host header injection attacks.
exploitationpenetration-testingvulnerability-analysis+2

Captures password reset tokens from Mailcow Host header injection attacks.
PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

Docker-based multi-stage attack emulation lab demonstrating CVE-2017-5638 and CVE-2021-41773 exploitation, lateral movement, and Suricata IDS…

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.