
npm-demo
Browser demo: EJS template injection (CVE-2022-29078) with Seal Security remediation

Browser demo: EJS template injection (CVE-2022-29078) with Seal Security remediation
PoC for Unauthenticated Reflected Cross-Site Scripting (XSS) in RegistrationMagic WordPress Plugin

Proof-of-concept for CVE-2026-27472 (blind SSRF) and CVE-2026-27474 (stored XSS) in SPIP 4.4.8 syndication feature, demonstrating exploitation steps…

Reflected XSS vulnerability disclosure for ZenShare Suite login_newpwd.php, allowing arbitrary JavaScript execution via crafted URL in codice_azienda…

The ZenShare Suite application is vulnerable by a Reflected Cross-Site Scripting (XSS) vulnerability, affecting web application login and recovery…

CVE-2022-29117 (.NET Cookie-Handling DoS) Assessment, Understanding & Questions Framework

Reflected XSS via search GET Parameter in Phoca Download

Exploit for CVE-2023-39361 in Cacti, a network graphing solution, demonstrating SQL injection vulnerability for educational and security testing…

Root-cause analysis and safety-gated verification tool for CVE-2025-0324, a privilege-escalation flaw in AXIS OS VAPIX allowing any authenticated…

🫖 Contract-correlated discovery and authorized validation tool for Gitea CVE-2026-60004

Python script to discover admin panel URLs of websites, aiding in security reconnaissance and penetration testing.

A lightweight extension to automatically detect and provide verbose warnings for embedded iframe elements in order to protect against…

Automated PoC for CVE-2026-48611 — phpBB OAuth login_link authentication bypass

PoC and detection templates for pre-auth RCE and payment tampering in Balbooa Forms (Joomla), including Python exploit and Nuclei detection template.

Read-only CLI to check whether a WordPress site is exposed to WP2Shell (CVE-2026-63030 / CVE-2026-60137)

Intentionally vulnerable CGI lab for Shellshock (CVE-2014-6271) with a Python RFC-3875 server and GNU bash 4.2, designed for isolated security…

Browser resource exhaustion payload that crashes target systems via memory, GPU, audio, and rendering overload. Designed for authorized security…

Safe passive detector for identifying WPMU DEV Dashboard versions affected by CVE-2026-76581.