
CVE-2022-22965_Spring4Shell
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit…

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit…

Improper Hostname Verification in EagleEyes Lite Android Application

Cross-Site Scripting (XSS) Vulnerability in Fiora Chat Application

Improper Certificate Chain Validation in EagleEyes Lite Android Application

The vulnerability exists in the Student Payment API. The application fails to properly validate whether the user requesting a receipt is authorized…

🔗 Lightweight security orchestrator mobile application for URI vetting, providing a unified, multi-engine interface to aggregate and validate link…

The exploitation module for the CVE-2019-19781 #Shitrix (Vulnerability in Citrix Application Delivery Controller and Citrix Gateway).

Cleartext Transmission of Sensitive Information in EagleEyes Lite Android Application

CVE-2022-29359 - School Application System Stored Cross-Site Scripting

Exploit in Rails Development Mode. With some knowledge of a target application it is possible for an attacker to guess the automatically generated…

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

(deprecated) Android application vulnerability analysis and Android pentest tool

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Automatic SSTI detection tool with interactive interface

Python script to inject existing Android applications with a Meterpreter payload.

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

CuckooDroid - Automated Android Malware Analysis with Cuckoo Sandbox.

Java-based framework for systematic fuzzing and analysis of TLS libraries. Enables arbitrary protocol message crafting, modification, and testing of…