
CVE-2025-68400
Technical disclosure of a critical time-based blind SQL injection vulnerability (CVE-2025-68400) in ChurchCRM, including vulnerable code analysis,…

Technical disclosure of a critical time-based blind SQL injection vulnerability (CVE-2025-68400) in ChurchCRM, including vulnerable code analysis,…

Security research & exploitation analysis of CVE-2025-55182 (React) — CVSS + OWASP Top 10 mapping

Proof of concept demonstrating insecure AES-CBC encryption with MD5 key derivation in the Meesho Android app, enabling ciphertext tampering and…

A comprehensive analysis of CVE-2021-41773 (Apache HTTP Server 2.4.49), featuring vulnerability research, controlled lab-based exploitation,…

An advanced command-line framework for discovery, validation, and exploitation of CVE-2025-55182 and CVE-2025-66478 affecting Next.js applications…

In-depth technical analysis of Cisco ISE RCE vulnerabilities, including exploitation techniques, evasion methods, and remediation strategies for…

Exploit for Drupal CVE-2018-7602 remote code execution vulnerability via double URL encoding bypass of sanitize() filter. Includes Docker-based lab…

This room is based on exploiting the notorious Log4j vulnerability ( CVE-2021-44228), also referred to as the Log4Shell. The weakness enables…

Demo of the algorithm confusion attack on various JWT libraries

Educational cybersecurity project demonstrating exploitation and mitigation of CVE-2020-25213 (WordPress File Manager Plugin RCE). Includes malware…

PoC of CVE-2025-30921

A quick and dirty PoC of cve-2021-26084 as none of the existing ones worked for me.

Unauthenticated Denial of Service in DLink consumer DIR 819 A1 router

This is Metasploit module who exploit the command injection vulnerability in control center of the agent Tesla.

Step-by-step walkthrough of exploiting CVE-2022-22965 (Spring4Shell) with Metasploit, deploying a C2 listener, and mitigating the vulnerability by…

Testing a List of IP address incase they are vulnerable to CVE-2024-3400

Full walkthrough of HTB's Reactor machine — exploit CVE-2025-55182 to gain a shell, then get root via an exposed Node.js debugger. Step-by-step with…

Fork of github.com/spring-projects/spring-data-rest (vulnerable to CVE-2017-8046)