
IFA
PoC exposing a critical IndexedDB vulnerability that enables a disk flooding attack by exploiting the lack of restrictions.

PoC exposing a critical IndexedDB vulnerability that enables a disk flooding attack by exploiting the lack of restrictions.

Quick WAF "paranoid" Doctor Evaluation | WAFPARAN01D3 Tool

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

Proof-of-concept exploit for CSRF to RCE in Backdrop CMS 1.20 (CVE-2021-45268) using malicious plugin upload.

Proof-of-concept exploit for CVE-2026-1010, demonstrating WebSocket connection smuggling and request splitting through a malformed Upgrade header…

Educational FastAPI lab demonstrating CVE-2021-41773 directory traversal and local file inclusion, with a vulnerable server, patched code, and…

Hack The CCTV | DVRs; Credentials Exposed | CVE-2018-9995

Checks if your Chrome version is vulnerable to CVE-2025-5419, from the browser

PoC Docker lab: chaining file upload bypass + stored XSS to create admin accounts. Educational resource for pen testers.

Technical analysis and educational resource for CVE-2026-41940, covering root cause, scanner behavior, prevention, mitigation, IOC hunting, and VaPT…

Owa Valid Login Checker

CTF challenge replicating CVE-2025-31137 in Remix/React Router Express. Learn to exploit a server-side vulnerability to find the admin flag.

Proof of concept demonstrating Cross-Site Request Forgery (CSRF) on Avaya SCOPIA XT Desktop, allowing admin password change without anti-CSRF token.

Proof-of-concept for CVE-2026-25940 demonstrating embedded JavaScript execution via crafted AcroForm radio button appearances in PDF viewers, with…

Meow

CVE‑2025‑55182 Detection

Browser demo: EJS template injection (CVE-2022-29078) with Seal Security remediation

Proof-of-concept exploit for CVE-2025-29927 in Next.js 15.2.0, demonstrating a specific web application vulnerability for testing and educational…