
CVE-2021-3156-Mitigation-ShellScript-Build
Shell script that monitors for a vulnerable sudo process and triggers authentication lockout to mitigate CVE-2021-3156.

Shell script that monitors for a vulnerable sudo process and triggers authentication lockout to mitigate CVE-2021-3156.

The vulnerable application that will teach you how to hack WebSockets

Docker-based lab for reproducing Keycloak CVE-2026-18963, including vulnerable version setup, realm seeding, and source-level workflow analysis with…

Detection toolkit for CVE-2026-35616, a pre-authentication API bypass in FortiClient EMS. Includes Python scanner and Nmap NSE script for identifying…

CTF lab and exploit toolkit for CVE-2026-29000, a pac4j-jwt JWE authentication bypass. Includes vulnerable Flask target, token forging library,…

Library-level proof-of-concept lab demonstrating CVE-2026-29000 in pac4j-jwt, comparing vulnerable and patched versions with Docker to show forged…

Technical write-up of CVE-2026-26717, an HMAC timing attack in OpenFUN Richie LMS webhook authentication, including vulnerable code, impact, and fix…

Scanner for cPanel & WHM authentication bypass (CVE-2026-41940) that detects vulnerable versions via CRLF injection and session manipulation, with…

A Dockerized Redash instance that is vulnerable to CVE-2021-21239

Exploit for CVE-2023-7028 - GitLab CE/EE

ADCS cert template modification and ACL enumeration

Dahua IP camera CVE research toolkit (CVE-2021-33044/33045, CVE-2025-31700/31701)

Proof-of-concept exploit for CVE-2024-28987 targeting SolarWinds Web Help Desk hardcoded credential vulnerability. Automates exploitation via URL…

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

CVE-2025-0364: BigAnt Server RCE Exploit

Exploit for Red Hat / GlusterFS CVE-2018-1088 & CVE-2018-1112, featured @ DEFCON 26, Las Vegas!

This is the exploit of CVE-2019-17240.

JSON API User <= 3.9.3 - Unauthenticated Privilege Escalation