
CVE-2025-26465
MitM attack allowing a malicious interloper to impersonate a legitimate server when a client attempts to connect to it

MitM attack allowing a malicious interloper to impersonate a legitimate server when a client attempts to connect to it

A python script designed to check if the website if vulnerable of clickjacking and create a poc

Compact CVE reference: OS command injection in create-react-app before 5.0.2 on macOS via react-dev-utils openBrowser.js, including affected versions…

QloApp 1.5.2: Vulnerable to XSS on two Parameter (email_create and back)

Go-based automation tool that scans GitHub repositories for vulnerable Next.js versions (CVE-2025-66478) and automatically creates pull requests with…

Verify Next.js CVE-2025-29927 on Netlify not vulnerable

Proof-of-concept for stored XSS in Unifiedtransform v2.0's Create Assignment function, demonstrating remote code execution via malicious PDF upload…

PoC Docker lab: chaining file upload bypass + stored XSS to create admin accounts. Educational resource for pen testers.

Trigger-aware web server CVE audit for nginx and Apache. Goes beyond version matching by checking whether the vulnerable code path is actually…

Simple script to achieve safe and non-desruptive active detection of CVE-2026-72898 (SQLi in Metabase)

SonicWall security audit toolkit with vulnerable CTF lab (CVE-2021-20038, CVE-2024-53704)

GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

Python PoC for CVE-2026-3456 demonstrating OAuth2 PKCE race-condition account takeover, with a vulnerable auth server and concurrent code-verifier…

Proof-of-concept for CVE-2026-22005 showing OAuth 2.0 device code phishing via too-short polling interval, with vulnerable Flask server and exploit…

Exploit tool for CVE-2023-27524, an authentication bypass vulnerability in Apache Superset. Enables unauthorized access to vulnerable instances for…

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions including, 6.0.12. This is due to the plugin not properly…

Java-based wiki platform with detailed access control and JAAS security integration, provided as a vulnerable version for security testing and CVE…