
CVE-2022-32114
An unrestricted file upload vulnerability in the Add New Assets function of Strapi v4.1.12 allows attackers to execute arbitrary code via a crafted…

An unrestricted file upload vulnerability in the Add New Assets function of Strapi v4.1.12 allows attackers to execute arbitrary code via a crafted…

Modification of gitlab exploit anything under 13.10

Demonstration of the WP Visitor Statistics plugin exploit

Proof-of-concept exploit for CVE-2018-6574, demonstrating exploitation of a remote code execution vulnerability in Go-based applications.

CVE-2018-6389 WordPress Core - 'load-scripts.php' Denial of Service <= 4.9.4

This repository holds the advisory, exploits and vulnerable software of the CVE-2020-14293

Golang implementation of ThinVNC exploit CVE-2019-17662. For educational purposes only.

PoC of CVE-2023-29439

Educational PoC and analysis of CVE-2012-1823, a PHP-CGI remote code execution vulnerability. Includes Docker-based test environment, exploit…

This is a reproduction of PHP Laravel 8.70.1 - Cross Site Scripting (XSS) to Cross Site Request Forgery (CSRF) vulnerability

A demo of the CVE-2025-29927 vulnerability for a NebraskaJS lightning talk

Analysis and exploitation of a Next.js authorization bypass vulnerability (CVE-2025-29927)

Detection for CVE-2025-24016 - Deserialization of Untrusted Data Vulnerability in the Wazuh software

Deliberately vulnerable Next.js application designed for practicing exploitation of CVE-2025-29927, with a tutorial video for guided learning.

Demo of CVE-2025-29927 for secure programming class

Proof of calc for CVE-2019-6453

This is a special panel that is used to send POC requests with the output of responses.

Step-by-step walkthrough of CVE-2017-18349 Fastjson deserialization RCE exploitation, covering attack surface identification, fingerprinting, JNDI…