
CVE-2025-29927-NextJs-Middleware-Simulation
Simulates CVE-2025-29927, a critical Next.js vulnerability allowing attackers to bypass middleware authorization by exploiting the internal…

Simulates CVE-2025-29927, a critical Next.js vulnerability allowing attackers to bypass middleware authorization by exploiting the internal…

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

Custom PowerShell module to setup an Active Directory lab environment to practice penetration testing.


CVE-2025-29927 is a critical vulnerability in Next.js, a popular React-based web framework. The flaw exists in how the middleware feature handles…

Next.js Middleware Bypass Vulnerability

CVE-2025-29927: Next.js Middleware Exploit

PoC for CVE-2025-29927: Next.js Middleware Bypass Vulnerability. Demonstrates how x-middleware-subrequest can bypass authentication checks. Includes…

CVE-2025-29927 Proof of Concept

CF Internal Link Shortcode <= 1.1.0 - Unauthenticated SQL Injection

Advanced search in search engines, enables analysis provided to exploit GET / POST capturing emails & urls, with an internal custom validation…

Web Help Desk Hardcoded Credential Vulnerability (CVE-2024-28987)

This exploit was created to exploit an XXE (XML External Entity). Through it, I read the backend code of the web service and found an endpoint where…

A CobaltStrike toolkit to write files produced by Beacon to memory instead of disk

An ADCS honeypot to catch attackers in your internal network.

It is a simple script to automate internal port scanning dueto SSRF in requests-baskets v 1.2.1. this script can also assisst in solving 'SAU'…

Internal penetration testing tool for Linux that can be used to enumerate OS information, domain information, shares, directories, and users through…

Tool to discover external and internal network attack surface