

Host and manage multiple Juice Shop instances for security trainings and Capture The Flags



A simple python script to exploit CVE-2025-59528, this an Authenticated RCE vulnerability in Flowise application, a popular AI tool. That is also…

[First-Blood-XO] React Server Component endpoint vulnerable to CVE-2025-55182 (RCE) → enumerated SUID binaries → /usr/bin/perl had SUID set → used…

powerfull rust cve-2025-55182-scanner used for ctf & ethical purpose only

Archived CTF challenge sources and deployable sandboxes since 2017, with intentionally vulnerable exercises for hands-on security training and…

analysis of the sudo buffer overflow affect sudo version <1.8.26 and how to use GCC to compile publicly availible exploits

GTFO Command Line Interface for easy binaries search commands that can be used to bypass local security restrictions in misconfigured systems.

Chamilo LMS Unauthenticated Big Upload File that allows remote code execution


:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.

Automated ret2win exploit tool for CTF challenges. Finds stack offset, generates payloads, supports remote exploitation, and attaches GDB for…