
flask-vuln-baseline
Demonstrates CVE-2024-34064 in a Flask application without sanitization, serving as a baseline for security testing and educational analysis.

Demonstrates CVE-2024-34064 in a Flask application without sanitization, serving as a baseline for security testing and educational analysis.

Intentionally vulnerable Next.js application demonstrating CVE-2025-29927 middleware authorization bypass, designed for security testing and…

Dockerized PHP application providing hands-on XSS vulnerability challenges and bypass examples, including WAF, blacklist, and JavaScript validation…

A project demonstrating an app that is vulnerable to Spring Security authorization bypass CVE-2022-31692

Dockerized vulnerable Apache Struts application for testing CVE-2023-50164 remote code execution, with build and run instructions for security…

WARNING: This is a vulnerable application to test the exploit for the Really Simple Security < 9.1.2 authentication bypass (CVE-2024-10924). Run it…

Educational proof-of-concept exploit for CVE-2025-55182 targeting a React application, with Docker Compose environment for local testing and security…

Intentionally vulnerable Next.js application demonstrating CVE-2025-55182 RCE via unsafe deserialization in React Server Components. Includes exploit…

Demonstration application for CVE-2022-42889 (Apache Commons Text RCE) with Docker setup and netcat-based command execution for security testing and…

Proof-of-concept Next.js application demonstrating CVE-2025-55182 (React2Shell), a critical RCE in React Server Components, with exploit example and…

A self-hosted vulnerable Next.js environment running on Docker for simulating CVE-2025-55182. Built for educational security research and CTF…

Proof-of-concept application demonstrating CVE-2022-42889 RCE vulnerability in Apache Commons Text 1.9 with reproducible exploit steps for security…

Demonstrates CVE-2015-10034 in a vulnerable Java application, including SARIF analysis results from J-TAS Action for educational security testing.

automate CVE-2015-9235 exploitation

PoC exploit for CVE-2024-52302: unrestricted file upload in common-user-management Spring Boot app leading to remote code execution via…

CVE-2025-29927 is a critical security vulnerability affecting Next.js, a popular React framework for building full-stack web applications. This flaw…

A Stored Cross-Site Scripting (XSS) vulnerability exists in Issabel-PBX version 4.0.0-6. The application fails to properly sanitize and encode…

Intentionally vulnerable Next.js application demonstrating CVE-2025-29927 authentication bypass via middleware WAF evasion. Designed for security…