
Explosive-As-Hell-MCS-Qualifer-Web-500
[First-Blood-XO] React Server Component endpoint vulnerable to CVE-2025-55182 (RCE) → enumerated SUID binaries → /usr/bin/perl had SUID set → used…

[First-Blood-XO] React Server Component endpoint vulnerable to CVE-2025-55182 (RCE) → enumerated SUID binaries → /usr/bin/perl had SUID set → used…

AI-guided CTF - Break into a real server with Claude Code as your trainer

An interactive wizard front end for IVRE to make creating scans to the database easier.

Exploit CVE-2022-46363

ImageMagick Arbitrary Read Files - CVE-2022-44268

Lab + writeup for CVE-2026-44166: PocketBase OAuth2 account pre-hijacking via unvalidated createData.email

Exploit for the PHP 8.1.0-dev backdoor vulnerability (CVE-2021-21707)

Proof-of-Concept of CVE-2023-45612

CMS Made Simple < 2.2.10 - SQL Injection . Actual working version

A fun activity using a packet capture file from the log4j exploit (CVE-2021-44228)

jquery XSS Proof of Concept (PoC)

CVE-2025-2539 - File Away WordPress Plugin Arbitrary File Read

SecureOAuth-Demo: Laboratorio educativo que recrea de forma segura la vulnerabilidad CVE-2025-4679 (exposición de credenciales OAuth). Aprende…


Introduction to the exploitation of ELF binaries.

Hack The Box - Silentium machine writeup | CVE-2025-58434, CVE-2025-59528, CVE-2025-8110