
pocketbase-CVE-2026-44166
Lab + writeup for CVE-2026-44166: PocketBase OAuth2 account pre-hijacking via unvalidated createData.email

Lab + writeup for CVE-2026-44166: PocketBase OAuth2 account pre-hijacking via unvalidated createData.email

Exploitation de CVE-2022-22980

a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC). It also includes a realistic "Lab Environment" to safely test…

Python3 exploit for CVE-2019-9053 (CMS Made Simple <= 2.2.9 SQLi). No deps, time-based blind SQLi → admin creds dump. HTB Writeup owned.

CMS Made Simple < 2.2.10 - SQL Injection . Actual working version


A hands on lab investigating CVE-2025-39507 from a Tier 1 SOC analyst perspective. Includes log review in Microsoft Sentinel, IP analysis, real world…


🧱 CVE-2024-25600 WordPress Bricks Builder RCE Exploit + TryHackMe Bricks Heist CTF Write-up



Lab introduction to ZeroLogon

Created this exploit for the Hack The Box machine, Blurry.

Chamilo LMS Unauthenticated Big Upload File that allows remote code execution

Web application vulnerable to Python3 Flask SSTI (CVE-2019-8341)

exploit for CVE-2021-22911 in rust