
XSStrike
Advanced XSS detection suite with context-aware payload generation, multi-threaded crawling, WAF evasion, and DOM scanning for automated web security…

Advanced XSS detection suite with context-aware payload generation, multi-threaded crawling, WAF evasion, and DOM scanning for automated web security…

Intentionally vulnerable Next.js lab for CVE-2025-55182 exploitation research. Docker-packaged environment for practicing web application security…

Micro lab for CVE-2021-44228 (Log4Shell) with automated multi-target exploitation, runtime payload generation, and adjustable bypasses for security…

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

Web technology identification scanner with 1800+ plugins for detecting CMS, servers, JS libraries, and embedded devices. Supports stealthy to…

Perl-based web server scanner that performs comprehensive vulnerability checks, CGI scanning, and server fingerprinting with customizable plugins and…

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

Reproducer for CVE-2026-49042: demonstrates prompt injection in Apache Camel's langchain4j-tools leading to RCE via unfiltered Exchange headers.…

Docker-based Shellshock (CVE-2014-6271) exploit environment with ready-to-use attack scripts for CGI, SSH, and DHCP vectors. Includes vulnerable Bash…

Docker-based playground for testing CVE-2021-41773, demonstrating local file disclosure and remote code execution in Apache HTTPd 2.4.49.

Dockerized proof-of-concept for CVE-2022-42889 (Text4Shell) with script, DNS, and URL lookup-based RCE payloads for security testing and education.

Provides vulnerable Docker images for CVE-2021-41773 (Apache path traversal) with PoCs for file read and RCE, enabling security testing and practice.

Proof-of-concept exploit for CVE-2021-40438 (Apache mod_proxy SSRF) with Docker-based vulnerable environment for testing and validation.

Dockerized vulnerable environment for CVE-2018-11776 with proof-of-concept exploits, enabling hands-on testing of Apache Struts2 remote code…

PoC exploit for CVE-2025-32375 targeting BentoML 1.4.7, with a Docker-based vulnerable environment for testing and verification of the remote code…

Hands-on lab environment for testing Apache Tomcat unauthenticated RCE (CVE-2025-24813) with Docker setup and step-by-step exploitation guide.

Dockerized proof-of-concept exploit for CVE-2018-11776 (Apache Struts2) with a Go-based command execution payload for penetration testing and…

Dockerized exploit for OwnCloud CVE-2023-49103, providing a ready-to-use container for testing and validating the vulnerability in web application…