
pwnproxy
An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

CVE proof-of-concept labs, exploit scripts, and detection/prevention rules (Nginx, Apache, Snort, YARA) for high-severity CVEs. Authorized security…

Proof-of-concept exploit for an unauthenticated root authentication bypass in Proxmox VE 7.0-8.0.3, intended for authorized security testing and…

Proof-of-concept for CVE-2026-84361, demonstrating command injection in Composer's Perforce driver via malicious P4PORT, with Docker-based…

Browser demo: EJS template injection (CVE-2022-29078) with Seal Security remediation

The ZenShare Suite application is vulnerable by a Reflected Cross-Site Scripting (XSS) vulnerability, affecting web application login and recovery…

A lightweight extension to automatically detect and provide verbose warnings for embedded iframe elements in order to protect against…

Intentionally vulnerable CGI lab for Shellshock (CVE-2014-6271) with a Python RFC-3875 server and GNU bash 4.2, designed for isolated security…

Proof-of-concept for CVE-2026-18741, a stored XSS vulnerability in Worksuite SaaS Asset Management, demonstrating attacker-controlled JavaScript…

Technical advisory and proof-of-concept for CVE-2026-12513, an unauthenticated arbitrary file deletion via path traversal in Shared Files WordPress…

Intentionally vulnerable Log4j 2.14.1 HTTP service for hands-on practice with CVE-2021-44228 (Log4Shell) in an isolated sandbox environment.

Cracking utility to bypass premium access controls on Messari's research platform, enabling unauthorized access to premium reports and real-time…

Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078

Docker lab for reproducing CVE-2026-27541, an authenticated privilege escalation in WooCommerce Wholesale Prices. Compares vulnerable and patched…

Hack The Box Nexus machine write-up covering reconnaissance, Gitea credential discovery, Krayin CRM exploitation via CVE-2026-38526, initial access,…

End-to-end Docker lab reproducing Apache log4j2 #4255 — FilteredObjectInputStream allowlist bypass via java.rmi.MarshalledObject (unfiltered…

Check for CVE-2026-79266. A use-after-free in the DevTools component allows arbitrary code execution inside the sandbox via a malicious Chrome…

A security research tool for detecting and analyzing cPanel/WHM services and their authentication behavior. Designed for authorized testing and…