
CVE-2026-24061-setup
Docker setup for CVE-2026-24061

Docker setup for CVE-2026-24061

Runtime patches for algertc/alpr-dashboard: async logger fix and CVE-2025-29927 nginx mitigation

PoC for CVE-2025-29927: Next.js Middleware Bypass Vulnerability. Demonstrates how x-middleware-subrequest can bypass authentication checks. Includes…

Docker lab reproducing CVE-2026-71362 Magento/Adobe Commerce account takeover via customer-session identity switch, with PoC and official-patch A/B/A…

Docker lab reproducing CVE-2026-10795: UpdraftPlus UpdraftCentral authentication bypass chained to plugin installation for RCE. Includes…

Proof-of-concept exploit for CVE-2024-38821, demonstrating authentication bypass in Spring Framework via path traversal to access restricted…

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions including, 6.0.12. This is due to the plugin not properly…

CVE-2024-27198 & CVE-2024-27199 Authentication Bypass --> RCE in JetBrains TeamCity Pre-2023.11.4

Educational lab demonstrating CVE-2022-39227 JWT authentication bypass in python-jwt. Step-by-step attack against vulnerable and patched Flask apps…

Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

Non-destructive PoC and technical write-up for CVE-2026-73673, an unauthenticated firmware-update flaw in Netis NC63 router, with reproduction and…

Advisory and PoC for an unauthenticated authorization bypass in Typemill media downloads, using path-equivalent URL variants to access…

An open source, self-hosted implementation of the Tailscale control server

The full repo of all the labs available as part of the benchmark

Step-by-step lab writeup demonstrating CVE-2019-20933 InfluxDB authentication bypass via forged JWT tokens, including exploitation,…