
bunkerweb
🛡️ Open-source and cloud-native Web Application Firewall (WAF)

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

Python script to generate a malicious MP4 file and start a CherryPy web server hosting a simple HTML page with the embedded file. Exploits another…

Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution…

The flaw allows an attacker to execute arbitrary system commands on the server hosting the Pterodactyl Panel without any prior authentication.


Exploit script for Apache Struts2 REST Plugin XStream RCE (CVE-2017-9805)

CVE-2022-29221 Proof of Concept Code - Smarty RCE

Hooked browser communication over MQTT

Remote Code execution in CentOS web panel

Exploit script for Apache Struts2 REST Plugin XStream RCE (CVE-2017-9805)

POC For CVE-2020-7693 (Testing on Version [email protected])

CVE-2014-8731 - PHPMemcachedAdmin RCE - Proof of Concept

Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c


An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in…