


→ poc for CVE-2025-29927

Delivering PHP RCE (CVE-2024-4577) to the Local Network Servers

CVE-2025-29927: Next.js Middleware Exploit


A framework for identifying and launching exploits against internal network hosts. Works via WebRTC IP enumeration combined with WebSockets and…

Security awareness training tool for authorized phishing simulations and internal IT audits

SquirrellyJS mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration…

Proof-of-concept demonstrating an authorization bypass in Traefik's Kubernetes Gateway provider (CVE-2026-54761) via a crossProviderNamespaces…

Proof-of-concept exploit for CVE-2022-46364, an Apache CXF SSRF vulnerability enabling arbitrary file reads and internal network probing via crafted…

Script to exploit CVE-2018-1042 in order to do internal port scans.

CF Internal Link Shortcode <= 1.1.0 - Unauthenticated SQL Injection

Just proof of concept for Cisco CVE-2020-3452. Using external or internal file base.

Simulates CVE-2025-29927, a critical Next.js vulnerability allowing attackers to bypass middleware authorization by exploiting the internal…

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

A ESP32-S3–based usb keylogger with wifi, easy DIY-able with widely available hardware.

CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4