
HTB-TwoMillion-machine
Hack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.

Hack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.

Automated vulnerable Active Directory lab suite for practicing penetration testing techniques, with prebuilt domains/forests and standalone attack…

A compact guide to network pivoting for penetration testings / CTF challenges.

The repo contains a series of challenges for learning Frida for Android Exploitation.

CVE-2026-60004 — Gitea <= 1.27.0 Pre-Auth RCE

Local privilege escalation via TOCTOU race condition in PackageKit's.

Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.

Collection of penetration testing tools

Create your own vulnerable by design AWS penetration testing playground

🛡️ CVE Proof-of-Concept Hub — 4 PUBLISHED CVEs · 5 under review (VulnCheck) · SuiteCRM batch withdrawn

RedRoot is a Python-based, CLI-driven offensive security framework that brings essential red teaming tools into one unified terminal environment.…

Linux kernel privilege-escalation exploit for CVE-2026-46242, a race-condition use-after-free in epoll, with 99% reliable root on desktops, servers,…

Multi-architecture Linux privilege escalation toolkit with 24 pre-built and runtime-compilable exploits. Auto-detects kernel version, filters patched…

Gogs service Exploit and get the root user

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

This cheasheet is aimed at the CTF Players and Beginners to help them understand the fundamentals of Privilege Escalation with examples.