
HAFNIUM-Microsoft-Exchange-0day
CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065

CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065

Zap Extension for collaboration in Faraday

Sets up a Docker-based Palo Alto firewall test environment and provides an exploit script to test CVE-2024-3400, enabling safe vulnerability…

Proof-of-concept exploit for CVE-2026-42945, a heap buffer overflow in NGINX rewrite/set directives, enabling DoS and potential RCE via crafted…

Local read-only scanner for CVE-2026-42945 (NGINX Rift) that checks NGINX, OpenResty, and Tengine instances for vulnerable rewrite configurations…

Proof-of-concept demonstrating a stored XSS vulnerability in Juzaweb CMS v5.0.0 via the banner ads HTML field, leading to arbitrary script execution…

Proof-of-concept exploit for GitLab stored XSS (CVE-2022-1175) enabling personal access token theft and account takeover via malicious issue comments.

Proof-of-concept for CVE-2022-2466 demonstrating unauthenticated GraphQL request context termination in Quarkus/SmallRye, bypassing authorization…

CVE-2025-33053 Checker and PoC

Docker-based vulnerable environment for practicing CVE-2023-30212 exploitation, featuring an OURPHP web app with a reflected XSS vulnerability for…

Test tool for CVE-2024-26144 that checks if web servers and CDNs improperly cache HTTP responses containing Set-Cookie headers, revealing cache…

Scans for CVE-2024-52301, an argument injection vulnerability in Laravel, using subfinder and httpx to identify affected web applications.

CVE-2019-14222: Default Certificate in Alfresco Community

YARPP <= 5.30.10 - Missing Authorization

Proof-of-concept for CVE-2025-25749 demonstrating weak password policy in HotelDruid 3.0.7, with automated test scripts and mitigation…

Comprehensive Java utility library providing modules for cryptography, HTTP client, caching, JSON, scripting, and captcha generation, simplifying…

Stereotyped Challenges (2014~2023)