
WebSecProbe
Security testing tool for analyzing HTTP 403 responses and identifying access control misconfigurations in web applications.

Security testing tool for analyzing HTTP 403 responses and identifying access control misconfigurations in web applications.

Exploit PoC for CVE-2026-27579, a CORS misconfiguration in Appwrite backend, demonstrating credentialed account data theft via malicious phishing…

Proof-of-concept and analysis for CVE-2020-1947, a YAML deserialization remote code execution vulnerability in Apache ShardingSphere UI, including…

Hacking Artifactory with server side template injection

Solar Appscreener XXE

CVE-2019-12409: RCE Vulnerability Due to Bad Defalut Config in Apache Solr

TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight…

Django-based CTF blog platform with integrated CVE-2021-35042 exploit tool for learning web application security and vulnerability exploitation.

Tool for helping in the exploitation of path traversal vulnerabilities in Java web applications

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Python exploit for MoziloCMS <= 3.0.1 that uploads a PHP web shell via authenticated admin access, renames the file, and executes system commands on…

PHP Webshell with handy features

Automated SQL injection detection and exploitation tool for extracting database information from web applications, supporting multiple injection…

Proof-of-concept exploit for CVE-2026-41096, demonstrating the vulnerability and providing a reproducible test case for security researchers and…

🛡️ Official AI Security Tool module for CVE-2026-21858 + CVE-2025-68613 (n8n "Ni8mare" Unauthenticated Arbitrary File Read & Expression Injection…

Control Web Panel (CWP) vulnerability scenario related to CVE-2026-57517

CVE-2025-24813-POC JSP Web Shell Uploader

Mass exploitation tool for CVE-2024-4358, executing commands on multiple web targets concurrently with threading support.