
CVE-2024-53677-Exploitation
Step-by-step walkthrough for exploiting Apache Struts CVE-2024-53677 RCE via file upload manipulation, including OGNL injection, payload embedding,…

Step-by-step walkthrough for exploiting Apache Struts CVE-2024-53677 RCE via file upload manipulation, including OGNL injection, payload embedding,…

Proof-of-concept for CVE-2024-57484: directory listing vulnerability in FoxyProxy extension exposing internal file structure and metadata, enabling…

PoC and exploit for CVE-2021-41773 path traversal in Apache HTTP Server 2.4.49, with Docker setup and curl-based exploitation commands for file…

In-depth analysis of CVE-2024-38819, a Spring WebFlux file traversal vulnerability, with code-level breakdown, PoC, and mitigation strategies…

Restrict Content <= 3.2.7 - Information Exposure via legacy log file

Detailed incident report analyzing CVE-2024-24919 arbitrary file read exploit on Check Point Security Gateway, including technical analysis, response…

Demonstrates CVE-2026-35492, a path traversal vulnerability in kedro-datasets PartitionedDataset allowing arbitrary file write, with impact analysis…

Proof-of-concept exploit for CVE-2026-7482, an unauthenticated heap out-of-bounds read in Ollama's GGUF loader, demonstrating memory exfiltration via…

Proof-of-concept exploit for CVE-2026-21440, a critical path traversal in AdonisJS multipart uploads enabling arbitrary file write and remote code…

Proof-of-concept exploits for CVE-2026-19912, CVE-2026-19913, and CVE-2026-19914, demonstrating file read and remote code execution in Kaltura,…

Proof-of-concept reproducers for Apache Camel camel-google-storage path traversal (CVE-2026-66907), demonstrating arbitrary file write via…

Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application

Modular Burp Suite extension for fine-grained highlighting and extraction of sensitive data from HTTP and WebSocket traffic, enabling efficient…

Curated collection of bug bounty writeups covering OWASP Top 10 vulnerabilities, including XSS, SQLi, SSRF, and RCE, for educational learning and…

Cross-site scripting labs for web application security enthusiasts


Make URL path combinations using a wordlist
