
CVE-2025-64512-Polyglot-PoC
A Proof-of-Concept for CVE-2025-64512 using a polyglot file.

A Proof-of-Concept for CVE-2025-64512 using a polyglot file.

The VMWare Horizon Connection Server is often used as an internet-facing gateway to an organization’s virtual desktop environment (VDI). Until…

Yetishare SQL Injection in sSortDir_0 parameter - v3.5.2 - v4.5.4. Apart from an admin being able to exploit this, it could also be used in a CSRF…

Burp-Automator: A Burp Suite Automation Tool with Slack Integration. It can be used with Jenkins and Selenium to automate Dynamic Application…

This is a tool used by several security researchers to find Carriage Return Line Feed Injection Bug

This is a tool used by several security researchers to find Open Redirect Bug

Simple scanner to detect vulnerable Livewire installations.

A curated list of CTF frameworks, libraries, resources and softwares


🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could…

simple urls < 115 - Reflected XSS

Example and demo setup for Heartbleed vulnerability (CVE-2014-0160). This should be used for testing purposes only!💔

Rewe API reverse engineering in Go

CVE-2026-33693: SSRF via 0.0.0.0 Bypass in activitypub-federation-rust v4_is_invalid() (CVSS 6.5 Moderate)


a lightweight, flexible and novel open source poc verification framework