
CVE-2025-55182-research
🛡️ Explore CVE-2025-55182, a critical RCE vulnerability in React's Flight Protocol, demonstrating exploitation techniques and mitigation strategies.

🛡️ Explore CVE-2025-55182, a critical RCE vulnerability in React's Flight Protocol, demonstrating exploitation techniques and mitigation strategies.

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…


Test authentication bypass vulnerabilities in cPanel and WHM using this proof of concept exploit tool written in Go.

Proof-of-concept for CVE-2026-19500, a DoS vulnerability in the SureForms WordPress plugin that exhausts server resources via oversized key-value…

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Collaborative application security testing between humans and agents via CLI and MCP

CVE-2026-74970 · Fission site isolation bypass in Firefox WebRender

Proof-of-concept exploit for CVE-2026-59310, demonstrating remote path traversal via crafted syslog messages to write arbitrary log files on VMware…

Modular penetration testing framework integrating multiple tools for automated web application security assessment, aligned with OWASP Testing Guide,…

Proof-of-concept exploit for Apache Struts S2-072 (CVE-2026-73633), demonstrating CPU and memory exhaustion by sending crafted JSON requests to the…

PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover (CVSS 6.8)

my poc for CVE-2026-53787

mencari sebuah kerentanan, wodpres dan mengungah shell di kerentanan wodpres tersebut

Exploit for CVE-2026-64638, a pre-authentication reflected XSS in WordPress login, enabling injection of malicious JavaScript into /wp-login.php…

Proof-of-concept HTML page that reproduces CVE-2019-10070, a cross-site scripting vulnerability in Apache Atlas, for validation and defensive testing.

WordPress Core <= 7.0.3 - Authenticated (Author+) Remote Code Execution via Malicious File Upload

CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4