
nextjs-lodash-cve-2025-13465-repro
Reproduction environment for CVE-2025-13465, demonstrating a vulnerability in Next.js applications using Lodash. Provides a minimal setup to test and…

Reproduction environment for CVE-2025-13465, demonstrating a vulnerability in Next.js applications using Lodash. Provides a minimal setup to test and…

Automated blind-xss search for Burp Suite

BurpSuite插件,用于自动化执行blind-xss盲搜索。它能够执行主动和被动检查。

A round-trip obfuscated HTTP file transfer setup built to bypass IDS detections.

Dockerfile containing all the necessary setup files to demo the exploit

The goal of this project is to demonstrate the log4j cve-2021-44228 exploit vulnerability in a spring-boot setup, and to show how to fix it.

Some setup scripts for security research tools.

Docker image and commands to check CVE-2019-11043 vulnerability on nginx/php-fpm applications.

Demonstration of the Heartbleed CVE (CVE-2014-0160), including lab setup instructions and source code to build your own Heartbleed lab for…

White-box CMS security scanner that audits core, plugin, and theme versions, detects unauthorized modifications, and cross-references known…

Educational proof-of-concept replicating CVE-2021-38297, a Go WASM buffer overflow leading to stored XSS. Includes vulnerable app setup, exploit…

It is possible to view the MD5 hash of the admin password and other attributes without authentication, even after initial setup and password change.…

Educational lab demonstrating CVE-2026-2964, a prototype pollution vulnerability in web-audio-recorder-js leading to RCE. Includes vulnerable and…

Proof-of-concept exploit for CVE-2025-9519, demonstrating remote code execution in WordPress Easy Timer plugin via a crafted shortcode filter, with…

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

MagicArch is a comprehensive post-installation script built with Ansible, designed to transform a basic Arch Linux installation into a fully equipped…

CTF challenge exploiting CVE-2025-0184 DOCX SSRF vulnerability to access internal admin service and retrieve a flag. Includes exploit generator and…

This experiment is destinated to demonstrate how the DNS rebinding attack works on an emulated IoT. In the setup, we have a simulated IoT device,…