
CVE-2022-22965
Proof-of-concept exploit and testing scripts for Spring4Shell (CVE-2022-22965), a Spring Framework remote code execution vulnerability, with bash and…

Proof-of-concept exploit and testing scripts for Spring4Shell (CVE-2022-22965), a Spring Framework remote code execution vulnerability, with bash and…

PoC for testing reflected XSS in Swagger UI via CVE-2019-1749; sends crafted payloads and verifies vulnerable endpoints with minimal setup.

CVE-2026-63077 — Unauthenticated Remote Code Execution in JetBrains TeamCity via agent polling protocol deserialization. CVSS 9.8 CRITICAL. Mass…

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

Exploit PoCs for CVE-2025-30374, a Taipy class pollution bug, demonstrating RCE, reflected XSS, DoS, and OpenAI credential leakage with Docker-based…

Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting PoC

Proof-of-concept exploit for CVE-2026-1010, demonstrating WebSocket connection smuggling and request splitting through a malformed Upgrade header…

Proof-of-concept exploits for critical SharePoint RCE vulnerabilities (CVE-2024-38094, CVE-2024-38024, CVE-2024-38023) with demonstration video.

Wordell is a powerful WordPress enumeration script designed to make your WordPress security assessments more efficient and comprehensive. It enables…

Small Python library that makes it easy to exploit race conditions in web apps with Requests.

SPIP (CVE-2024-23659) script with native python3 dependencies

AIRecon is an autonomous cybersecurity agent that combines a self-hosted Large Language Model (Ollama) with a Kali Linux Docker sandbox and a Textual…

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

Capture-the-flag challenge for Ekoparty 2020 featuring a Flask web application with security vulnerabilities to exploit. Designed for hands-on…

Structured curriculum for learning application security, covering secure coding, threat modeling, and DevSecOps practices. Designed for self-paced…

Christmas-themed CTF Advent Calendar with 12 structured challenges across binary exploitation, cryptography, reverse engineering, forensics, OSINT,…

Curated collection of Python scripts and tutorials for penetration testing, web security, and exploitation techniques, designed for security…

OWASP-maintained Top 10 API security risks document and documentation portal with best practices for building, breaking, and defending APIs.