
gf
A wrapper around grep, to help you grep for things

A wrapper around grep, to help you grep for things

Docker-based exploit for CVE-2024-835 vulnerability with automated deployment via docker-compose for penetration testing and security assessment.

Proof-of-concept reproducing CVE-2026-48206 header injection in Apache Camel camel-jira, demonstrating authorization bypass via user-controlled…

Reproducer for CVE-2026-49042: demonstrates prompt injection in Apache Camel's langchain4j-tools leading to RCE via unfiltered Exchange headers.…

Reproducer for CVE-2026-49099 demonstrating SOQL injection via HTTP header override in Apache Camel camel-salesforce, with mock Salesforce backend…

PoC reproducer for CVE-2026-53913 demonstrating a fail-open authentication bypass in Apache Camel's camel-keycloak, leading to unauthenticated RCE…

GUI Burp Plugin to ease discovering of security holes in web applications

Docker-based Shellshock (CVE-2014-6271) exploit environment with ready-to-use attack scripts for CGI, SSH, and DHCP vectors. Includes vulnerable Bash…

Java XML serialization library with a focus on CVE-2021-21345 exploit analysis and deserialization vulnerability testing for web applications.

Intentionally vulnerable Next.js lab for CVE-2025-55182 exploitation research. Docker-packaged environment for practicing web application security…

Dockerized exploit for OwnCloud CVE-2023-49103, providing a ready-to-use container for testing and validating the vulnerability in web application…

Micro lab for CVE-2021-44228 (Log4Shell) with automated multi-target exploitation, runtime payload generation, and adjustable bypasses for security…

Reproducer for CVE-2026-46726 demonstrating WebSocket header injection in Apache Camel camel-vertx-websocket enabling SSRF and property-placeholder…

Reproducer for CVE-2026-46592 demonstrating SOAP operation redirection via operationName header injection in Apache Camel camel-cxf, enabling…

Reproducer for CVE-2026-46456: Apache Camel camel-aws2-sqs inbound message-attribute header injection enabling downstream producer steering and RCE…

Reproducer for CVE-2026-46455 demonstrating Apache Camel camel-keycloak authentication bypass via missing TokenVerifier.IS_ACTIVE check, allowing…

Educational proof-of-concept exploit for CVE-2025-55182 targeting a React application, with Docker Compose environment for local testing and security…

Isolated research lab and proof-of-concept for validating a SharePoint deserialization vulnerability (CVE-2025-53770) with a Python exploit driver,…