
Struts2-045-Exp
Struts2 S2-045(CVE-2017-5638)Exp with GUI

Struts2 S2-045(CVE-2017-5638)Exp with GUI

Scans exported Azure domain dumps for plaintext passwords, connection strings, storage keys, and other secrets; generates redacted CSV/HTML reports…

reversing mtk-su

A transparent PII redaction proxy for LLM API traffic. Sits between an application and an LLM provider (currently Anthropic), pseudonymizing…


Phase C&C Blind SQL Injection


Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints

CVE-2026-87902 detector. WordPress get_page_template LFI class. Detect-only. Authorized lab.

Lab vulnerável (Docker) + PoC Python para a CVE-2026-87902 — path traversal não autenticado no WordPress Core (page-template -> LFI -> RCE…

Local Privilege Escalation in polkit's pkexec (CVE-2021-4034)

Parallel SSH service discovery and security auditor that scans any port, validates SSH banners, and audits authentication methods, weak cryptography,…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Stack buffer overflow PoC for a hardware wallet USB descriptor parser (CVE-2026-22013), showing return-address overwrite and code execution via…

Unauthenticated SQL Injection via Attribute Filter in Phoca Cart - CVSS 9.3

Modification of Metasploit module for RCE in Ruby-On-Rails Console CVE-2015-3224

Coq-based formal verification of a Linux kernel eBPF verifier vulnerability (CVE-2020-8835) with reproducible build environment and proof artifacts.

CVE-2021-44228