
CVE-2023-38408
Proof-of-concept exploit for CVE-2023-38408, demonstrating exploitation of a remote code execution vulnerability in a targeted application or service.

Proof-of-concept exploit for CVE-2023-38408, demonstrating exploitation of a remote code execution vulnerability in a targeted application or service.

Proof-of-concept exploit for CVE-2025-52399, demonstrating SQL injection in the Institute-of-Current-Students application via the loginlinkfaculty…

OS Command Injection Vulnerability via Plugin Execution in Figma Desktop Application

A Java application intentionally vulnerable to CVE-2021-44228

The exploitation module for the CVE-2019-19781 #Shitrix (Vulnerability in Citrix Application Delivery Controller and Citrix Gateway).

Grails sample application using the Javamelody 1.44 plugin to illustrate the CVE-2013-4378 vulnerability.

Simple Vulnerable Spring Boot Application to Test the CVE-2021-44228

CVE-2022-42889 dockerized sample application (Apache Commons Text RCE)

Demonstrates exploitation of CVE-2017-8046 in a Spring Boot application, including a SpEL injection payload and dependency-check verification for…

Exploit in Rails Development Mode. With some knowledge of a target application it is possible for an attacker to guess the automatically generated…

CVE-2022-29359 - School Application System Stored Cross-Site Scripting

Proof-of-concept exploit for CVE-2021-44228 (Log4Shell) that automates LDAP and HTTP servers to deliver a reverse shell payload to a vulnerable Java…

Hands-on Dev Container environment for exploring CVE-2022-22970 with a vulnerable Spring application and proof-of-concept exploit code.

Proof-of-concept for a blind XSS vulnerability in Maid Hiring Management System v1.0, capturing admin session cookies via a crafted application form…

Remote code execution exploit for Citrix Application Delivery Controller and Gateway (CVE-2019-19781) that executes arbitrary commands on vulnerable…

PoC exploit for CVE-2019-9081 targeting Laravel deserialization RCE. Includes a pre-built vulnerable Laravel 5.7.x application and payload generator…

WARNING: This is a vulnerable application to test the exploit for the Cacti command injection (CVE-2023-39362). Run it at your own risk!

This is a dockerized application that is vulnerable to the Spring4Shell vulnerability (CVE-2022-22965).