
CVE-2026-1281-CVE-2026-1340-Ivanti-EPMM-RCE
A simple demo application that shows how to reproduce the Ivanti EPMM pre-auth RCE vulnerability (CVE-2026-1281 / CVE-2026-1340) for educational and…

A simple demo application that shows how to reproduce the Ivanti EPMM pre-auth RCE vulnerability (CVE-2026-1281 / CVE-2026-1340) for educational and…

🛠 Demonstrate remote code execution in Windows Notepad via markdown links exploiting unsecured URL protocols.

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

Next generation web scanner


Java XML serialization library with a focus on CVE-2021-21345 exploit analysis and deserialization vulnerability testing for web applications.

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…


Automatic SSTI detection tool with interactive interface

A wrapper around grep, to help you grep for things

Exploit for Jenkins serialization vulnerability - CVE-2016-0792

A collection of useful resources for hacking WordPress and it's plugins and themes

Laravel debug mode - Remote Code Execution (RCE)

Deliberately vulnerable Next.js application demonstrating CVE-2025-29927 middleware bypass exploit for security testing and educational practice.

a Damn Vulnerable Serverless Application

The vulnerable application that will teach you how to hack WebSockets

In Dolibarr 17.0.0 with the CMS Website plugin (core) enabled, an authenticated attacker can obtain remote command execution via php code injection…

Proof-of-concept exploit for CVE-2026-0013, demonstrating a remote code execution vulnerability in a target application. Includes payload generation…