
CVE-2020-10770-keycloak-exploit-poc
Step-by-step guide to reproduce the Keycloak blind SSRF vulnerability (CVE-2020-10770) with Docker setup, listener configuration, and mitigation…

Step-by-step guide to reproduce the Keycloak blind SSRF vulnerability (CVE-2020-10770) with Docker setup, listener configuration, and mitigation…

Joomla 1.5 - 3.4.5 Object Injection RCE X-Forwarded-For header

[discontinued] Mass exploiter of CVE-2015-1579 for WordPress CMS

Browser demo: EJS template injection (CVE-2022-29078) with Seal Security remediation

The vulnerable application that will teach you how to hack WebSockets

Unauthenticated RCE scanner for FortiSandbox CVE-2026-39808 with canary-based verification, command execution, and pipeline integration for mass…

Proof-of-concept for CVE-2026-25940 demonstrating embedded JavaScript execution via crafted AcroForm radio button appearances in PDF viewers, with…

Proof-of-concept demonstrating arbitrary code execution in Orval via malicious OpenAPI fields, with setup, exploit steps, and remediation guidance.

Proof of concept for stored HTML injection in RISE CRM, demonstrating how authenticated users can inject malicious HTML into invoices and messages,…

Proof-of-concept for an authentication bypass in PerfexCRM prior to 3.3.1, demonstrating how empty credentials can grant unauthorized admin access.

A simple demo application that shows how to reproduce the Ivanti EPMM pre-auth RCE vulnerability (CVE-2026-1281 / CVE-2026-1340) for educational and…

Python exploit script for CVE-2026-23744 that delivers a reverse shell to a specified target URL, requiring a netcat listener for command-and-control.

Proof-of-concept reproducer for Apache Camel camel-atmosphere-websocket dispatch header injection (CVE-2026-71300), demonstrating how an injected…

Tips on how to write exploit scripts (faster!)

Educational CVE-2026-11107 demo with vulnerable Flask API and exploit script, showing how predictable UUIDv1 identifiers enable insecure direct…

Burp Plugin to Bypass WAFs through the insertion of Junk Data


Proof-of-concept exploit for CVE-2026-1010, demonstrating WebSocket connection smuggling and request splitting through a malformed Upgrade header…