
cve-2018-11776
Docker container providing a vulnerable Apache Struts2 environment for CVE-2018-11776 exploitation practice and security education.

Docker container providing a vulnerable Apache Struts2 environment for CVE-2018-11776 exploitation practice and security education.

Windows 11-first educational lab for studying CVE-2025-1974 in ingress-nginx. Provides safe attack emulation and defense validation with local…

Docker container providing a vulnerable environment for CVE-2019-10678, designed for security training and exploitation practice within the Cved…

PoC and Disclosure for CVE-2023-7231 – Memcached Gopher RCE chain

Monitors cryptographic integrity of container images, releases, and Git tags for supply chain security, verifying Sigstore cosign signatures with…

This is a simple PoC that allows you to highlight the severity of the ongoing and actively exploited Telnet bug that is going on right now. Why…

A simple Docker lab and Exploit setup for CVE-2021-3156 - "Baron Samedit".

PoC for CVE-2025-1974: Critical RCE in Ingress-NGINX (<v1.12.1) via unsafe config injection. Exploitable from the pod network without credentials,…

Containerized CTF lab for learning and exploiting CVE-2025-64424, a command injection RCE in Coolify. Includes vulnerable environment, walkthrough,…

Docker-based lab environment for exploiting Apache HTTP Server 2.4.50 path traversal and RCE vulnerability (CVE-2021-42013) with automated exploit…

A self-hosted vulnerable Next.js environment running on Docker for simulating CVE-2025-55182. Built for educational security research and CTF…

React2Shell (CVE-2025-55182) – An intentionally vulnerable Next.js application created for educational and research purposes.

Reproduction and fix of the CVE-2025-29927 vulnerability.

Educational proof-of-concept exploit for CVE-2025-55182 targeting a React application, with Docker Compose environment for local testing and security…

Exploit for CVE-2019-19030 that affects Harbor versions <1.10.3 and <2.0.1. Can also be used to enumerate and pull public projects from higher…

Docker-based lab for practicing WordPress CVE-2024-1071 exploitation with automated PoC scripts and step-by-step setup instructions.

In-depth technical analysis of CVE-2025-1974 (IngressNightmare), a critical RCE in ingress-nginx validating admission controller for Kubernetes,…

Junior Backend Candidate Exercise: Packaging the dasel CLI (v3.3.1) with Melange, fixing CVE-2026-33320, and building a minimal container image using…