
WordPressMassExploiter
[discontinued] Mass exploiter of CVE-2015-1579 for WordPress CMS

[discontinued] Mass exploiter of CVE-2015-1579 for WordPress CMS

Browser demo: EJS template injection (CVE-2022-29078) with Seal Security remediation

Learn how I found my first two CVEs by pure accident.

The vulnerable application that will teach you how to hack WebSockets

CVE-2026-0073 is an RCE with a CVSS severity score of 8.3, and here we will explain how it works.

Proof-of-concept for CVE-2026-25940 demonstrating embedded JavaScript execution via crafted AcroForm radio button appearances in PDF viewers, with…

Analyzes CVE-2021-42948, a session token exposure vulnerability in HotelDruid, demonstrating how GET parameters leak session IDs and enable session…

Proof of concept for stored HTML injection in RISE CRM, demonstrating how authenticated users can inject malicious HTML into invoices and messages,…

I Found a Zero-Day Vulnerability in langchain — Here’s How It Went

Analyzes CVE-2024-38998, a prototype pollution vulnerability in requirejs 2.3.6, demonstrating how malicious config inputs can lead to DoS, RCE, or…

A simple program to demonstrate how Log4j vulnerability can be exploited ( CVE-2021-44228 )

Summary of Cyber Security interview questions I have been through, hope this helps

Tips on how to write exploit scripts (faster!)

how to look for Leaked Credentials !

Burp Plugin to Bypass WAFs through the insertion of Junk Data

A OSINT project that explores how to dump data from React

Proof-of-concept exploit for CVE-2026-1010, demonstrating WebSocket connection smuggling and request splitting through a malformed Upgrade header…

Quick WAF "paranoid" Doctor Evaluation | WAFPARAN01D3 Tool