
challenge_CVE-2020-13777
Challange CVE-2020-13777

Challange CVE-2020-13777

Proof-of-concept exploit for CVE-2019-6690, demonstrating input validation bypass in python-gnupg symmetric encryption via newline injection in…

proof of concept for CVE-2020-0601

Educational PoC and analysis of CVE-2025-68621, a timing attack on Trilium Notes sync login. Demonstrates HMAC hash recovery via network timing…

Analysis of CVE-2016-3959 and a Proof of Concept Attack Against a Go SSH Server.


CVE-2026-39031 — offline plaintext password recovery for Lansweeper lsrunase 2.0 / lsencrypt 2.0 via a hardcoded RC4 key. PoC + technical advisory.

Implementation of the byte-at-a-time ECB oracle attack against AES-ECB encryption. Decrypts ciphertexts by feeding chosen plaintexts to a block…

Proof-of-concept exploit for CVE-2022-0778, a denial-of-service vulnerability in OpenSSL's BN_mod_sqrt() function, with Docker-based lab environment…

Custom vulnerable VM (Ubuntu 14.04) designed for teaching multi-stage penetration testing. Features 10 interconnected challenges across Forensics,…

Demonstration of Go's dsa.Verify bug (CVE-2019-17596)

CVE-2022-37177 - HireVue-Broken-Or-Risky-Cryptographic-Algorithm

Reappear-CVE-2022-21449-TLS-PoC

CVE-2024–27632 Reference

Example script demonstrating a weak PRNG, CVE-2008-0166

Educational Jupyter notebook demonstrating the Dual_EC_DRBG cryptographic backdoor (CVE-2014-8610) with NIST P-256 state recovery attack, historical…

Simplified Version of Cryptography Attack based on Birthday Paradox: Sweet32 (CVE-2016-2183)