
waf-checker
Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Step-by-step guide to reproduce the Keycloak blind SSRF vulnerability (CVE-2020-10770) with Docker setup, listener configuration, and mitigation…

Proof-of-concept reproducer for Apache Camel camel-atmosphere-websocket dispatch header injection (CVE-2026-71300), demonstrating how an injected…

The vulnerable application that will teach you how to hack WebSockets

Educational CVE-2026-11107 demo with vulnerable Flask API and exploit script, showing how predictable UUIDv1 identifiers enable insecure direct…

Proof-of-concept exploit for CVE-2026-1010, demonstrating WebSocket connection smuggling and request splitting through a malformed Upgrade header…

Educational FastAPI lab demonstrating CVE-2021-41773 directory traversal and local file inclusion, with a vulnerable server, patched code, and…

Proof-of-concept exploit for CVE-2024-24824 demonstrating how an arbitrary class loading primitive can be transformed into remote code execution on…

This lab demonstrates the exploitation of CVE-2024-24945, a heap corruption vulnerability affecting NGINX. The objective was to understand how memory…

Research of exploit options for CVE-2024-53667 and their remediation

Lightweight Python script to test username/password combinations against Zimbra webmail login pages for security assessments and password auditing.

Proof-of-concept exploit for CVE-2026-32136: unauthenticated authentication bypass in AdGuard Home via HTTP/2 cleartext (h2c) upgrade. Demonstrates…

Unauthenticated RCE scanner for FortiSandbox CVE-2026-39808 with canary-based verification, command execution, and pipeline integration for mass…

This vulnerability allows an attacker to perform SSRF (Server-Side Request Forgery) attacks on Apache CXF webservices that accept MTOM/XOP requests.…

PoC Docker lab: chaining file upload bypass + stored XSS to create admin accounts. Educational resource for pen testers.

Python exploit script for CVE-2026-23744 that delivers a reverse shell to a specified target URL, requiring a netcat listener for command-and-control.

PoC for CVE-2024-36039: Demonstrating SQL Injection via PyMySQL Object-to-String serialization flaw

SEH-based buffer overflow in Easy File Sharing Web Server 7.2 demonstrating how an authenticated HTTP POST parameter can corrupt the exception…