
struts_cve-2024-53677
Proof-of-concept exploit and detection script for Apache Struts CVE-2024-53677 (S2-067), including a Docker-based vulnerable lab environment for…

Proof-of-concept exploit and detection script for Apache Struts CVE-2024-53677 (S2-067), including a Docker-based vulnerable lab environment for…

Nightingale Docker for Pentesters is a comprehensive Dockerized environment tailored for penetration testing and vulnerability assessment. It comes…

Intentionally vulnerable Next.js RSC Docker lab for CVE-2025-55182 (React2Shell) local testing

Automated WAF security testing tool that detects false positives and false negatives using 15+ payload categories including SQLi, XSS, RCE, and…

Vulnerable docker container for Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass CVE-2023-50164

Proof-of-concept demonstrating stored XSS in RosarioSIS 8.2.1 with Docker setup and step-by-step payload execution for security testing.

Docker-based reproduction of CVE-2017-7529 (Nginx integer overflow) for security testing and education. Part of the Cved vulnerable container…

Isolated Docker lab and non-destructive Python scanner reproducing CVE-2026-94545, the Next.js next/og ImageResponse SVG injection, with vulnerable…

This repository provides a Docker container for simulating the CVE-2023-30212 vulnerability, allowing you to practice and understand its impact. It…

Security training for the apps you actually ship. Open your browser and start hacking.

Single-file PoC for Rails CVE-2026-66066: arbitrary file read, secret recovery, threaded scanning, and conditional RCE via signed image variations.

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

Lightweight Python utility for automated security auditing of GraphQL APIs. Detects misconfigurations, information leaks, and denial-of-service…

Opensource, cross-platform and portable toolkit for automating routine processes when carrying out various works for testing!

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…


Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens