
Principal-HackTheBox
Detailed walkthrough of exploiting CVE-2026-29000 in pac4j-jwt to bypass authentication, extract credentials from API settings, and escalate…

Detailed walkthrough of exploiting CVE-2026-29000 in pac4j-jwt to bypass authentication, extract credentials from API settings, and escalate…


CVE-2026-39031 — offline plaintext password recovery for Lansweeper lsrunase 2.0 / lsencrypt 2.0 via a hardcoded RC4 key. PoC + technical advisory.

Proof-of-concept exploit for CVE-2026-26012, a broken access control in Vaultwarden that allows any organization member to enumerate and decrypt all…

Demonstration of Go's dsa.Verify bug (CVE-2019-17596)

Simplified Version of Cryptography Attack based on Birthday Paradox: Sweet32 (CVE-2016-2183)

Reappear-CVE-2022-21449-TLS-PoC

CVE-2022-37177 - HireVue-Broken-Or-Risky-Cryptographic-Algorithm

CVE-2024–27632 Reference

Example script demonstrating a weak PRNG, CVE-2008-0166

Demo of CVE-2021-27568: Insecure randomness in token generation

Educational Jupyter notebook demonstrating the Dual_EC_DRBG cryptographic backdoor (CVE-2014-8610) with NIST P-256 state recovery attack, historical…

AES-CFB IV Generation Vulnerability in Reolink Desktop Application

Full-lifecycle penetration test of a legacy Linux environment (Metasploitable 2) emulated on Apple Silicon. Demonstrating network reconnaissance, RCE…

Custom vulnerable VM (Ubuntu 14.04) designed for teaching multi-stage penetration testing. Features 10 interconnected challenges across Forensics,…

Responsible disclosure write-up for CVE-2025-14175 involving weak cryptographic algorithm support in the SSH server of TP-Link TL-WR820N.

(CVE-2023-31290) Trust Wallet Core before 3.1.1, as used in the Trust Wallet browser extension before 0.0.183, allows theft of funds because the…

Perl version of recently published scripts to build ECC certificates with specific parameters re CVE-2020-0601