
XXStrike
XSStrike based XSS scanner with custom features. Detects XSS vulnerabilities in web applications.

XSStrike based XSS scanner with custom features. Detects XSS vulnerabilities in web applications.

Proof-of-concept for CVE-2026-79303, a critical boolean-blind SQL injection in Kaiten affecting order_by and order_direction parameters, with…

Stored XSS via Location Title in DPCalendar Free

Demonstrates a stored XSS vulnerability in lunary-ai/lunary's Analytics component, where unsanitized NEXT_PUBLIC_CUSTOM_SCRIPT injection leads to…

WordPress Passster Plugin <= 4.2.18 is vulnerable to Cross Site Scripting (XSS)

Proof-of-concept and detailed writeups for CVE-2024-57487 (authenticated RCE via file upload) and CVE-2024-57488 (stored XSS) in Online Car Rental…

YAML-based proof-of-concept for CVE-2025-59528, demonstrating remote code execution in Flowise via the CustomMCP node's unsafe JavaScript evaluation.

A wrapper around grep, to help you grep for things

Security Advisory: HTTP Response Splitting via Unvalidated Response Header Values (rouille)

CVE-2025-60374: Stored Cross-Site Scripting (XSS) in Perfex CRM Chatbot

A collection of useful resources for hacking WordPress and it's plugins and themes

Demo environment for CVE-2022-22980 (Spring Data MongoDB SpEL injection RCE) with vulnerable application code for security testing and education.

GUI Burp Plugin to ease discovering of security holes in web applications

Web application security scanner created by lcamtuf for google - Unofficial Mirror

Educational exploit demo for CVE-2018-1263 (phpMyAdmin RCE/LFI). Includes vulnerable environment setup via Docker and step-by-step attack walkthrough…

Java XML serialization library with a focus on CVE-2021-21345 exploit analysis and deserialization vulnerability testing for web applications.

Detailed technical analysis of CVE-2022-24760, a prototype pollution vulnerability in parse-server leading to remote code execution via BSON…

Educational analysis and proof-of-concept exploit for CVE-2022-22965, a Spring MVC/WebFlux remote code execution vulnerability via data binding on…