

DejaVU - Open Source Deception Framework

Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)

Open-source interactive security awareness training library with 130+ SCORM exercises covering phishing, vishing, BEC, MFA fatigue, and OWASP AI/LLM…

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Docker-based lab and exploit script for CVE-2024-23897, a critical arbitrary file read in Jenkins CLI via args4j expandAtFiles, with steps to chain…

Cyber threat intelligence platform for SSL certificate discovery, domain/URL scanning, data leak monitoring, tracking link generation, and threat…

FreePBX 未认证SQL注入导致远程代码执行,FreePBX 15 (低于 15.0.66)、16 (低于 16.0.89)、17 (低于 17.0.3)。该漏洞位于商业化“endpoint”模块中,因对用户输入过滤不严,允许未认证的攻击者绕过管理员权限,执行SQL注入,并最终实现远程代码执行

AI agent framework for black-box security testing with autonomous multi-agent orchestration, built-in pentesting tools, and MCP integration for bug…

PoC for CVE-2026-63030 + CVE-2026-60137, AKA WP2Shell


A vulnerable version of Rails that follows the OWASP Top 10

Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

Apache Syncope: User self-service privilege escalation

This demo application partially covers the vulnerability CVE-2024-38828

A list of Capture The Flag (CTF) frameworks, libraries, resources and software for started/experienced CTF players 🚩