
CVE-2021-43650
Webrun <= 3.6.0.42 SQLi

Webrun <= 3.6.0.42 SQLi
Analyse SQL injection attempts in web server logs

A collection of web pages vulnerable to SQL injection flaws

Local GeoServer/PostGIS lab reproducing OGC Filter SQL injection (CVE-2023-25157/25158) with vulnerable, patched, and mitigated A/B test modes.

Demonstration of the WP Visitor Statistics plugin exploit

Proof-of-concept exploit for CVE-2026-37068: arbitrary file write in Veno File Manager 4.4.9 via authenticated POST request to /vfm-admin/index.php.

mooSocial v3.1.8 is vulnerable to cross-site scripting on Invite Friend function.

A XSS vulnerability exists in in React Router's meta()/<Meta> APIs in Framework Mode when generating script:ld+json tags which could allow arbitrary…

Reflected XSS exploit PoC for GLPI (CVE-2024-27914) targeting unauthenticated debug mode. Provides a malicious link to trigger XSS in administrator's…

The most powerful CRLF injection (HTTP Response Splitting) scanner.

Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more

Web application penetration testing lab — vulnerable Flask app, automated scanner, and professional pentest report. Covers OWASP Top 10, SQLi, XSS,…


A modular framework for benchmarking LLMs and agentic strategies on security challenges across HackTheBox, TryHackMe, PortSwigger Labs, Cybench,…

Offensive Docker is an image with the more used offensive tools to create an environment easily and quickly to launch assessment to the targets.

Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.

Mass scanner and exploit for CVE-2026-15989, the unauthenticated privilege escalation in Super Forms <= 6.3.316 that creates administrator accounts…

A comprehensive Security Operations Centre (SOC) incident response simulation demonstrating threat detection, triage, analysis, and mitigation of the…