
DVSA
a Damn Vulnerable Serverless Application

a Damn Vulnerable Serverless Application

application server attack toolkit

Remote Code Execution Exploit for Citrix Application Delivery Controller and Citrix Gateway [ CVE-2019-19781 ]

A command-line scanner for batch detection of Next.js application versions and determining if they are affected by CVE-2025-66478 vulnerability.

Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.

Damn Vulnerable C# Application (API)

Collaborative application security testing between humans and agents via CLI and MCP

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

In Dolibarr 17.0.0 with the CMS Website plugin (core) enabled, an authenticated attacker can obtain remote command execution via php code injection…

Remote Code Execution Exploit for Citrix Application Delivery Controller and Citrix Gateway [ CVE-2019-19781 ]

CVE-2019-5893 | OpenSource ERP application has SQL Injection vulnerability.

CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC…

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit…

Cross-Site Scripting (XSS) Vulnerability in Fiora Chat Application

The vulnerability exists in the Student Payment API. The application fails to properly validate whether the user requesting a receipt is authorized…

The exploitation module for the CVE-2019-19781 #Shitrix (Vulnerability in Citrix Application Delivery Controller and Citrix Gateway).

CVE-2022-29359 - School Application System Stored Cross-Site Scripting

Exploit in Rails Development Mode. With some knowledge of a target application it is possible for an attacker to guess the automatically generated…