
VulnerableGWTApp
An intentionally-vulnerable GWT-based web application to test tooling and techniques

An intentionally-vulnerable GWT-based web application to test tooling and techniques

ShellShock attack and exploit detector for Bro.

HTTP/2 Bomb: HPACK indexed-reference amplification + flow-control stall. A high school student's full protocol analysis (LaTeX). CVE-2026-49975,…

CY376 Blue Team project — pfSense DMZ, Suricata IDS/IPS, and automated host hardening against CVE-2014-6271

Compact CVE reference: OS command injection in create-react-app before 5.0.2 on macOS via react-dev-utils openBrowser.js, including affected versions…

Apache HTTPd (2.4.49) – Local File Disclosure (LFI)

Proof-of-concept exploit for CVE-2020-0601 (Windows CryptoAPI spoofing) that generates rogue CA certificates to intercept HTTPS traffic, with…

Defensive remediation and auditing toolkit for CVE-2026-54420 in LiteSpeed cPanel Plugin. Automates patching, detects suspicious symlinks, hunts…

Automated web security auditing tool that detects environment misconfigurations, probes backend vulnerabilities, and bypasses WAF/IDS protections…

Proof-of-Concept exploit for CVE-2015-9251, a cross-site scripting (XSS) vulnerability in jQuery versions prior to 3.0.0, demonstrating attack…

Unauthenticated Jenkins CLI exploit scanner for CVE-2024-23897 that detects vulnerable versions and reads arbitrary files from the controller through…

WordPress FEUP Arbitrary File Upload Exploit (CVE-2025-2005)

Proof-of-concept script to detect vulnerable Sitecore instances by analyzing server response headers for specific modifications, aiding in…

Proof-of-concept exploit demonstrating an XSS vulnerability in ARD's Ajax transaction manager endpoint through unsanitized accountName input,…

Bitrix Vulnerability CVE-2022-43959

Proof-of-concept exploit for an authentication bypass vulnerability (CWE-565) in WP Private Content Plus v3.6.2, allowing unauthenticated access to…

Security Advisory: Unauthenticated Path Traversal Allows Arbitrary File Read (TinyWeb)

CVE Reproduction: cve-2026-34486-tomcat_encrypt_bypass_reproduction