



Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2…

Burp Suite extension to generate Intruder payloads using Radamsa

CVE-2019-14540 Exploit

adaptive agents for dynamic web penetration testing

Burp Suite extension to detect the Next.js / React Server Components (RSC) Remote Code Execution vulnerability (CVE-2025-55182 & CVE-2025-66478).

A Burp Suite extension that integrates Dalfox XSS scanner directly into your workflow.

Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known…

A minimalistic LDAP server that is meant for test vulnerability to JNDI+LDAP injection attacks in Java, especially CVE-2021-44228.

Log4j漏洞(CVE-2021-44228)的Burpsuite检测插件

CVE-2025-24813利用工具

Vulnerability scanner for Spring4Shell (CVE-2022-22965)

Burp Active Scan extension to identify Log4j vulnerabilities CVE-2021-44228 and CVE-2021-45046

这里保存着我学习CVE-2012-1889这个漏洞的利用所用到的文件

SEH-based buffer overflow in Easy File Sharing Web Server 7.2 demonstrating how an authenticated HTTP POST parameter can corrupt the exception…

Stack-based buffer overflow in Sync Breeze Enterprise 10.0.28 reachable through the /login handler, demonstrating how unchecked input length can…

remote debug environment for CLion