
Reverse-Engineering
A FREE comprehensive reverse engineering tutorial covering x86, x64, 32-bit/64-bit ARM, 8-bit AVR and 32-bit RISC-V architectures.

A FREE comprehensive reverse engineering tutorial covering x86, x64, 32-bit/64-bit ARM, 8-bit AVR and 32-bit RISC-V architectures.

Docker lab for reproducing CVE-2025-11262, an unauthenticated stored blind XSS in Link Whisper Free WordPress plugin. Includes vulnerable and patched…

Xiaomi HyperOS AVCodec Medya Framework'ündeki Use-After-Free (CVE-2025-21082) Zafiyetinin Derinlemesine Analizi, Rust Simülasyonu ve İnteraktif Web…

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…

Free hands-on digital forensics labs for students and faculty

Proof-of-concept exploit for CVE-2025-62215, a Windows kernel Use-After-Free vulnerability in SepTokenSidSharingEnabled. Includes a kernel driver and…

Some good resources for getting started with application security

A curated list of hacking environments where you can train your cyber skills legally and safely

Ronin is a Free and Open Source Ruby Toolkit for Security Research and Development. Ronin also allows for the rapid development and distribution of…

Local privilege escalation proof-of-concept for CVE-2023-20938, a use-after-free in Android binder, achieving root and disabling SELinux on…

Fastjson 1.2.83 RCE 靶场环境 (CVE-2026-16723)

Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.

An OWASP-aligned intentionally vulnerable platform for learning and testing AI, LLM, RAG, MCP, and Agentic AI security.

Exploit for CVE-2026-46215, a Linux kernel DRM GEM use-after-free local privilege escalation. Uses racing, slab spraying, and Dirty Pipe-style file…

Local privilege escalation exploit for CVE-2023-52927, a Use-After-Free vulnerability in the Linux kernel netfilter subsystem, with a KASAN trigger…

PoC for the recent critical vuln affecting OpenSSH versions < 9.3p2

Educational standalone JavaScript implementation of the public exploit for CVE-2016-9079 (Firefox Use-After-Free), adapted from the original…

Proof-of-concept demonstrating a Use-After-Free vulnerability in Firefox's RTCEncodedFrameBase via WebRTC Encoded Transforms, enabling heap…