
Next.js-Middleware-Bypass-CVE-2025-29927-
CTF challenge to learn and practice exploiting the Next.js middleware bypass vulnerability (CVE-2025-29927) by finding a flag in an admin page.

CTF challenge to learn and practice exploiting the Next.js middleware bypass vulnerability (CVE-2025-29927) by finding a flag in an admin page.

CTF challenge replicating CVE-2025-31137 in Remix/React Router Express. Learn to exploit a server-side vulnerability to find the admin flag.

Tests your WAF with +160 payloads

Proof of Concept - RCE Exploitation : Web Shell on Apache Tomcat - Ensimag January 2018

Local lab for understanding CVE-2025-55182 RCE in React Server Components/Next.js. Includes a deliberately vulnerable app and optional scanner helper…

CVE-2019-6340 Drupal 8.6.9 REST Auth Bypass examples

Proof-of-concept for an authentication bypass in PerfexCRM prior to 3.3.1, demonstrating how empty credentials can grant unauthorized admin access.

Proof of concept showing how CVE-2016-2098 leads to remote code execution

Struts2 Application Vulnerable to CVE-2017-5638. Explains how the exploit of the vulnerability works in relation to OGNL and the JakartaMultiPart…

Seal Security example — vulnerable npm app (EJS CVE-2022-29078) remediated to sealed versions; GitHub Actions + Jenkins integration

Seal Security example — vulnerable Maven app (SnakeYAML CVE-2022-1471) remediated to sealed versions; GitHub Actions + Jenkins integration

Proof-of-concept exploit for CVE-2023-27350 authentication bypass in PaperCut MF/NG, allowing unauthenticated interaction with vulnerable print…

On Thursday (December 9th), a 0-day exploit in the popular Java logging library log4j (version 2) was discovered that results in Remote Code…

This container was made to explain and demonstrate how CVE-2019-15813 (Sentrifugo works)

Artefacts for blog post on finding CVE-2025-37899 with o3

just remeber how small mistake in santisize username could give yoy root access to the full machine

CVE-2025-54100 (CVSS 7.8 High) is a command injection vulnerability in the Invoke-WebRequest cmdlet of Windows PowerShell 5.1. It arises from…

WordPress pentest tool