

React2shell vulnerable lab (CVE-2025-55182)

autonomous red teaming platform; multi-agent offensive-security meta-harness

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.

Exploits by 1N3 @CrowdShield @xer0dayz @XeroSecurity

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

RedRoot is a Python-based, CLI-driven offensive security framework that brings essential red teaming tools into one unified terminal environment.…

An implementation of a vulnerable MCP server using mcp-go

Unauthenticated RCE on cups-browsed (exploit and nuclei template)

CVE-2026-60004 — Gitea <= 1.27.0 Pre-Auth RCE

Proof-of-concept exploit for an authentication bypass in marimo's terminal WebSocket endpoint, enabling unauthenticated command execution in versions…

Hack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.

This is an edited version of the CVE-2018-19422 exploit to fix an small but annoying issue I had.

The full repo of all the labs available as part of the benchmark