
CVE-2020-36287
The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from…

The dashboard gadgets preference resource of the Atlassian gadgets plugin used in Jira Server and Jira Data Center before version 8.13.5, and from…

Proof-of-concept exploit for CVE-2024-27316, an HTTP/2 CONTINUATION flood vulnerability in Apache httpd, demonstrating resource exhaustion via…

Proof-of-concept exploit for CVE-2022-41401, a server-side request forgery (SSRF) vulnerability in OpenRefine <= v3.5.2, enabling unauthorized…

PoC Docker lab: chaining file upload bypass + stored XSS to create admin accounts. Educational resource for pen testers.

IFRIT is an AI-powered reverse proxy that intercepts incoming requests in real time, classifying each one as legitimate or malicious. Legitimate…

Proof-of-concept for Denial of Service (DoS) attacks against WordPress 4.9.8 and 5.5 via unauthenticated requests to vulnerable admin pages, causing…

Proof-of-concept exploit for CVE-2014-7816 targeting Undertow Java web server, demonstrating a directory traversal vulnerability in the HTTP server's…

Proof-of-concept exploit for SQL injection vulnerability in SourceCodester Human Resource Management System 1.0, enabling unauthenticated admin login…

Proof-of-concept for CVE-2024-34221: insecure permission vulnerability in SourceCodester Human Resource Management System 1.0 allowing unauthorized…

Proof-of-concept exploit for CVE-2022-46104 demonstrating a reflected XSS vulnerability in the Human Resource Management System login page.

Educational resource analyzing CVE-2024-21413 (Moniker Link) and its implications, providing insights into the vulnerability and broader…

Technical analysis and educational resource for CVE-2026-41940, covering root cause, scanner behavior, prevention, mitigation, IOC hunting, and VaPT…

Documentation of CVE-2025-56223, a denial-of-service vulnerability in Ascertia SigningHub's Upload Document API, allowing unrestricted file uploads…

Browser resource exhaustion payload that crashes target systems via memory, GPU, audio, and rendering overload. Designed for authorized security…

Security advisory detailing CVE-2026-50787, an uncontrolled resource consumption vulnerability in e-SIC Livre CAPTCHA generation, enabling remote…

Proof-of-concept for CVE-2026-36957, a denial-of-service vulnerability in Dbit Router firmware via HTTP flood on the Boa web server, causing resource…

A list of resources for those interested in getting started in bug bounties

Trail of Bits Testing Handbook - appsec.guide