
ULTIMATE-CYBERSECURITY-MASTER-GUIDE
This repository provides a centralized resource for operational cyber defense and offense, compiling Theory, Tools, Operating Procedures, and…

This repository provides a centralized resource for operational cyber defense and offense, compiling Theory, Tools, Operating Procedures, and…

Some good resources for getting started with application security

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

Deliberately vulnerable client-server application for learning penetration testing of non-HTTP thick clients. Includes challenges for SQL injection,…

Proof-of-concept for CVE-2018-1000529: stored XSS in Grails Fields plugin <=2.2.7. Demonstrates the vulnerability with a runnable Grails application…

This is a suite of tools/PoCs/exploits for cameras using the iCSee application. And yes - it can run NES games!

Deliberately vulnerable Next.js application designed for practicing exploitation of CVE-2025-29927, with a tutorial video for guided learning.

A simple python script to exploit CVE-2025-59528, this an Authenticated RCE vulnerability in Flowise application, a popular AI tool. That is also…

Intentionally vulnerable Next.js application demonstrating CVE-2025-29927 middleware authorization bypass, designed for security testing and…

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

CTF challenge container with a Next.JS middleware vulnerability (CVE-2025-29927) for practicing man-in-the-middle attacks and API exploitation.

PoC exploit for CVE-2024-1813: PHP object injection in Simple Job Board WordPress plugin, achieving unauthenticated RCE via gadget chain. Includes…

Proof-of-concept for unauthenticated stored XSS in SourceCodester Inventory System, demonstrating admin session hijacking via crafted registration…

Intentionally vulnerable Next.js app for CVE-2025-55182 security research and CTF challenges

A self-hosted vulnerable Next.js environment running on Docker for simulating CVE-2025-55182. Built for educational security research and CTF…

React2shell vulnerable lab (CVE-2025-55182)