
CVE
Collection of proof-of-concept exploit scripts for known CVEs targeting Linux kernels, Windows drivers, browsers, and web apps, for security research…

Collection of proof-of-concept exploit scripts for known CVEs targeting Linux kernels, Windows drivers, browsers, and web apps, for security research…

Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain

A collection of awesome penetration testing resources, tools and other shiny things

PoC for CVE-2026-54350 — Budibase unauthenticated NoSQL operator injection (CVSS 10.0). Read/mass-write any document collection via a PUBLIC query.

CVE-2026-48907

The full repo of all the labs available as part of the benchmark

A comprehensive collection of 12 containerized web exploitation challenges covering CVE-2023-25690, WebAuthn bypasses, HTTP/3 smuggling, and advanced…

A collection of useful resources for hacking WordPress and it's plugins and themes

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

A collection of selenium tests that might aid it takeover of a selenium node

PoC, Hunting React2Shell about CVE-2025-55182

ToolShell scanner - CVE-2025-53770 and detection information


Proof-of-Concept exploits for CVEs found by the team at Rhino Security Labs

JavaPayload is a collection of pure Java payloads to be used for post-exploitation from pure Java exploits or from common misconfigurations (like not…

A collection of proof-of-concept exploit scripts written by the team at Redway Security for various CVEs.

A collection of real world AI/ML exploits for responsibly disclosed vulnerabilities
