
React2Shell
Isolated Docker lab and static scanner for CVE-2025-55182, with vulnerable/patched Next.js builds and PoC validation of RSC Flight deserialization.

Isolated Docker lab and static scanner for CVE-2025-55182, with vulnerable/patched Next.js builds and PoC validation of RSC Flight deserialization.



Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known…

Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2…

adaptive agents for dynamic web penetration testing

CVE-2019-14540 Exploit

Burp Suite extension to generate Intruder payloads using Radamsa

Log4j漏洞(CVE-2021-44228)的Burpsuite检测插件

A minimalistic LDAP server that is meant for test vulnerability to JNDI+LDAP injection attacks in Java, especially CVE-2021-44228.

Burp Suite extension to detect the Next.js / React Server Components (RSC) Remote Code Execution vulnerability (CVE-2025-55182 & CVE-2025-66478).

SnakeYAML CVE-2022-1471 exploit payload for demo

POC for CVE-2025-24813 using Spring-Boot

remote debug environment for CLion

这里保存着我学习CVE-2012-1889这个漏洞的利用所用到的文件

Burp Active Scan extension to identify Log4j vulnerabilities CVE-2021-44228 and CVE-2021-45046