


nginx 1.15.10 patch against cve-2021-23017 (ingress version)

HTTP Proxy Analysis for reverse engineering protocol communication

Proof-of-concept exploit for CVE-2026-5029, delivering unauthenticated remote code execution via the run-code MCP tool on exposed HTTP endpoints.…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

REST API automation for Burp Suite Community Edition. Drop-in Java extension exposing send/repeat/history endpoints over a local HTTP API.

Safe PowerShell validator for PHP CVE-2026-17543 exposure via HTTP headers and non-destructive login-form probes.

Proof-of-concept exploit for CVE-2020-35669 demonstrating HTTP request smuggling and header injection in Dart's http package via crafted method…

Flask-like routing framework for mitmproxy to intercept, modify, and spoof HTTP requests/responses. Enables rapid development of MITM scripts for…

Proof-of-concept exploit for CVE-2026-1010, demonstrating WebSocket connection smuggling and request splitting through a malformed Upgrade header…

A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application that allows an attacker to perform unauthorized…

Shell script exploit for CVE-2019-16279 that triggers a denial-of-service via memory corruption by sending excessive CRLF sequences to an HTTP server.

Multi-target PoC runner for CVE-2026-1306 in WordPress midi-Synth plugin: fetches nonce, sends export AJAX request to upload files, and verifies…

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

A simple HTTP server for delivering and exfiltrating files/data during, for example, CTFs.

Discover input surfaces and security issues in compiled .NET assemblies — without running them.

CPH:SEC WAES: Web Auto Enum & Scanner - Auto enums website(s) and dumps files as result

Python PoC for CVE-2026-18907 path traversal in TECNO Hi Browser's download handler. Includes malicious HTTP server and naive downloader to…