
WordPressMassExploiter
[discontinued] Mass exploiter of CVE-2015-1579 for WordPress CMS

[discontinued] Mass exploiter of CVE-2015-1579 for WordPress CMS

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

Nuclei template to detect Apache servers vulnerable to CVE-2024-38473

CRLFMap is a tool to find HTTP Splitting vulnerabilities

POC of CVE-2023-35086 only DoS

Burpsuite Plugin For AES Crack

Simulated PoC for CVE-2025-2783 — a sandbox escape vulnerability in Chrome's Mojo IPC. Includes phishing delivery, memory fuzzing, IPC simulation,…

Async API security scanner in Rust for CORS, CSP, GraphQL, JWT, OpenAPI, and active API posture checks.

Nuclei templates and exploit resources for CRLF based desync attacks

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

Security advisory: Azure APIM Developer Portal allows cross-tenant account registration by bypassing UI signup restrictions. Reported to MSRC twice -…

A PoC to trigger CVE-2023-5217 from the Browser WebCodecs or MediaRecorder interface.

PoC for CVE-2021-43557

Proof-of-concept exploit for SonicWall SonicOS stack-based buffer overflows (CVE-2022-22274, CVE-2023-0656) that tests and triggers crashes via…

Apache APISIX Remote Code Execution (CVE-2022-24112) proof of concept exploit

Proof-of-concept exploit for CVE-2017-9096 demonstrating XML External Entity (XXE) injection in iText PDF library via malicious XMP metadata and form…

CVE-2020-36109 PoC causing DoS