
WebGoat
Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Proof-of-concept exploit for CVE-2025-29927, a Next.js middleware authorization bypass. Includes a vulnerable target lab and Python script to verify…

Automated All-in-One OS Command Injection Exploitation Tool

A/B Docker lab + PoC for CVE-2026-32475 (Elementor Pro Forms unauthenticated arbitrary file upload -> RCE via validation/move loop desync)

Unauthenticated account takeover PoC for TranslatePress Multilingual <= 3.3.1 (WordPress)

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Stored XSS via Location Title in DPCalendar Free

SQL Injection via ORDER BY Shortcode in plg_content_dpcalendar — DPCalendar Free ≤ 10.11.2

Python proof-of-concept for testing SMTP command injection (CVE-2026-73570) by sending malformed RCPT TO addresses to detect shell command…

Advanced Client-Side Prototype Pollution Scanner

CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting)…

Python framework exploiting CVE-2026-46339 for unauthenticated RCE on 9Router via MCP bridge, using temporal sharding and dispersion to evade…

Exploit and PoC for CVE-2026-67602, an authentication bypass in phpIPAM REST API via object-cache key collision, including a logic-level PoC and…

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

PoC, Dockerfile playground and root cause from patch diff analysis.

Proof-of-concept for CVE-2026-63039, demonstrating ORDER BY SQL injection in Apache InLong's AuditAlertRule via orderField/orderType, with a…

One-Day POC | GeoServer Unauthenticated SQL injection to complete RCE

110 offensive-security one-liners for authorized testing and CTFs, grouped by category and kill-chain step.