
CVE-2026-30252
The ZenShare Suite application is vulnerable by a Reflected Cross-Site Scripting (XSS) vulnerability, affecting web application login and recovery…

The ZenShare Suite application is vulnerable by a Reflected Cross-Site Scripting (XSS) vulnerability, affecting web application login and recovery…

An intentionally-vulnerable GWT-based web application to test tooling and techniques

NagaScan is a distributed passive vulnerability scanner for Web application.

A stored cross-site scripting (XSS) vulnerability in The Language Sloth Web Application v1.0 allows attackers to execute arbitrary javascript or HTML…

A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application that allows an attacker to perform unauthorized…

This project demonstrates a Web Application Firewall (WAF) simulation using Flask and a vulnerability checker for CVE-2017-5638. The WAF middleware…

Structured evaluation criteria framework for assessing Web Application Firewalls (WAFs), enabling users, vendors, and third parties to compare…

Exploit tool leveraging CVE-2026-350234 to obtain bilibili membership privileges, demonstrating web application vulnerability exploitation.

Proof-of-concept exploit for CVE-2026-41242 in a Node.js web application, demonstrating the vulnerability and potential impact.

Web application backdoor builder

Repository containing the DSpace 4.4 source code with a focus on CVE-2016-10726, providing a reference for vulnerability analysis and educational…

Proof-of-concept for CVE-2023-51214: a stored XSS vulnerability in a PHP-based activity log web application allowing remote code execution via…

Proof-of-concept exploit for CVE-2025-29927 in Next.js 15.2.0, demonstrating a specific web application vulnerability for testing and educational…

Springboot web application accepts a name get parameter and logs its value to log4j2. Vulnerable to CVE-2021-44228.

Web application vulnerable to Python3 Flask SSTI (CVE-2019-8341)

The Shadow Daemon web application firewall server

Change monitoring app that checks the content of web pages in different periods.

A vulnerable version of Rails that follows the OWASP Top 10