
cve-2025-39682
Linux kernel TLS zero-length record handling exploit for CVE-2025-39682, targeting kernelCTF mitigation instances with a 79% success rate.

Linux kernel TLS zero-length record handling exploit for CVE-2025-39682, targeting kernelCTF mitigation instances with a 79% success rate.

A fully red-team(offensive security) weaponized variant of wp2shell, built for authorized penetration testing & educational purposes.

CVE-2026-63030: WordPress REST batch-endpoint array desync. Mechanism, detection, mitigation, and a safe reproduction lab.

Walkthrough, threat analysis, and remediation guide for CVE-2017-0144 (EternalBlue).

Proof-of-concept exploit for CVE-2025-29927, demonstrating authentication bypass in Next.js middleware via the x-middleware-subrequest header, with…

Educational lab demonstrating EternalBlue (MS17-010) exploitation against Windows 7 using Metasploit, including post-exploitation, WannaCry…

Proof-of-concept exploit for CVE-2026-4480, an unauthenticated remote command execution in Samba's print subsystem via %J injection. Includes reverse…

Authenticated arbitrary file read exploit for the File Away WordPress plugin (CVE-2025-2539). Includes PoC, attack flow, detection signatures, and…

This lab demonstrates the exploitation of CVE-2024-24945, a heap corruption vulnerability affecting NGINX. The objective was to understand how memory…

Educational PoC for CVE-2026-8838, a critical RCE vulnerability in Amazon Redshift Python Driver via unsafe eval() in vector_in(). Includes technical…

Educational repository demonstrating XSS vulnerabilities in Django Rest Framework applications. Contains intentionally vulnerable code to teach…

PoC and mitigation for CVE-2019-9787 (WordPress XSS/CSRF/RCE). Demonstrates sanitization fixes, HttpOnly cookies, and hash-based CSRF defense with…