
CVE-2021-4034
Shell script that exploits CVE-2021-4034 (PwnKit) for local privilege escalation, intended for CTF use.

Shell script that exploits CVE-2021-4034 (PwnKit) for local privilege escalation, intended for CTF use.

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

Hack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.

A compact guide to network pivoting for penetration testings / CTF challenges.

The repo contains a series of challenges for learning Frida for Android Exploitation.

CVE-2026-60004 — Gitea <= 1.27.0 Pre-Auth RCE

Local privilege escalation via TOCTOU race condition in PackageKit's.

Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.

Personal collection of exploits including n-days, 0-days, CTFs, kernel and browser vulnerabilities for security research and penetration testing.

Collection of penetration testing tools

Create your own vulnerable by design AWS penetration testing playground

🛡️ CVE Proof-of-Concept Hub — 4 PUBLISHED CVEs · 5 under review (VulnCheck) · SuiteCRM batch withdrawn

RedRoot is a Python-based, CLI-driven offensive security framework that brings essential red teaming tools into one unified terminal environment.…

Capture-the-flag challenge for Ekoparty 2020 featuring a Flask web application with security vulnerabilities to exploit. Designed for hands-on…

Automated privilege escalation script exploiting misconfigured setuid/sgid binaries, sudo, cron, and LD_PRELOAD on Unix systems. Designed for CTF and…

Linux kernel privilege-escalation exploit for CVE-2026-46242, a race-condition use-after-free in epoll, with 99% reliable root on desktops, servers,…

Lab materials and practice resources for OSCP certification preparation, including penetration testing exercises and hands-on security training…