
CVE-2024-9707-Poc
he Hunk Companion Plugin for WordPress: Vulnerable to Unauthorized Plugin Installation/Activation (Versions Up to and Including 1.8.4)

he Hunk Companion Plugin for WordPress: Vulnerable to Unauthorized Plugin Installation/Activation (Versions Up to and Including 1.8.4)

Proof-of-concept exploit for CVE-2024-26026: unauthenticated SQL injection in F5 BIG-IP Next Central Manager API, enabling remote data extraction and…

Jenkins plugin for automated mobile app testing via Perfecto cloud, managing secure tunnel connections and app uploads within CI/CD pipelines.

Python-based Burp Suite extension is designed to detect the presence of CVE-2025-31324

A bash automation that exploits the vulnerable endpoints for the Joomla! API 4.0 - 4.2.7

Swift Performance Lite <= 2.3.6.14 - Missing Authorization to Unauthenticated Settings Export

CVE-2025-3855 - RISE Ultimate Project Manager - IDOR

Lightweight Java 8 web framework with routing, filters, and static file serving. Includes security advisory for older versions and CRUD API examples.

Lightweight Java 8 web framework for building REST APIs and web applications, with built-in routing, static file serving, and template engine support.

Here's a Python script that checks if the polyfill.io domain is present in the Content Security Policy (CSP) header of a given web application.

CodePath Assignment for Weeks 7 & 8: CVE-2017-14719, CVE-2019-9787 & Unauthenticated Page/Post Content Modification via REST API

Type-safe HTTP client library for Android and Java, enabling REST API communication with annotation-based request configuration and converter support.

Spring Cloud Config CVE-2019-3799|CVE_2020_5410 漏洞检测

Type-safe HTTP client for Android and Java with annotation-based API binding, converter support, and integration with OkHttp for network…

Burp Suite extension that intercepts requests and sends them over HTTP/3, converting responses back for Burp, with support for kettled requests and…

Black-box XXE scanner detecting in-band, error-based, and blind out-of-band injection via statistical baselining, parser fingerprinting, and OOB…

Extends Selenium's Python bindings to give you the ability to inspect requests made by the browser.

CVE-2025-41090 (brokeCLAUDIA): Broken access control in microCLAUDIA, the anti-ransomware platform by CCN-CERT.