
CVE-2020-0601_PoC
Demonstration of CVE-2020-0601 aka curveball. Based on the PoC's available at https://github.com/kudelskisecurity/chainoffools and…

Demonstration of CVE-2020-0601 aka curveball. Based on the PoC's available at https://github.com/kudelskisecurity/chainoffools and…

The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all…

Java classpath enumeration, focussed on CVE-2014-0043 for Apache Wicket 6.x

A vulnerable version of Rails that follows the OWASP Top 10

ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.

Trail of Bits Testing Handbook - appsec.guide

JAW: A Graph-based Security Analysis Framework for Client-side JavaScript


WordPress REST API SQLi to RCE PoC (CVE-2026-63030 & CVE-2026-60137)

Sourcecodester Zoo Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /classes/Login.php Due to invalid Content-Type

Browser demo: EJS template injection (CVE-2022-29078) with Seal Security remediation

Exploit for Apple CoreGraphics heap overflow (CVE-2014-4377) enabling arbitrary code execution on iOS 7.1.x via crafted PDF used as HTML image.

Exploit for SonicWall CVE-2019-7482 stack-based buffer overflow vulnerability, enabling remote code execution on affected firewall appliances.

Proof-of-concept exploit for CVE-2026-6960: unauthenticated arbitrary file upload in BookingPress Pro ≤ 5.6. Automates a 3-step chain to upload a PHP…

Exploit for CVE-2014-6271 (Shellshock) targeting Bash environment variable injection to achieve remote code execution on vulnerable systems.

Poc of SSRF for Request-Baskets (CVE-2023-27163)

Pre-auth RCE proof-of-concept chaining a WordPress REST batch API auth bypass with WP_Query SQL injection to dump hashes, add admin users, or plant a…

XSS Fuzzer is a tool which generates XSS payloads based on user-defined vectors and fuzzing lists.