


Unauthenticated RCE on cups-browsed (exploit and nuclei template)

Local privilege escalation via TOCTOU race condition in PackageKit's.

This is an edited version of the CVE-2018-19422 exploit to fix an small but annoying issue I had.

Hash database builder and reverse lookup tool — SHA256, RIPEMD160, Keccak256, BLAKE3 and more

The full repo of all the labs available as part of the benchmark



Step-by-step lab writeup demonstrating CVE-2019-20933 InfluxDB authentication bypass via forged JWT tokens, including exploitation,…

Full black-box penetration test against SecOS:1 (VulnHub) — CSRF exploitation, privilege escalation via CVE-2015-1328 (OverlayFS), post-exploitation

HTB Facts is a Easy Linux box featuring Camaleon CMS and MinIO. Gain admin access via open registration and a mass assignment vulnerability, then…

Spring4Shell (CVE-2022-22965) 漏洞環境搭建與 CTF 題目

Demonstration of the Heartbleed Bug CVE-2014-0160

How CVE-2025-29774 Vulnerabilities and the SIGHASH_SINGLE Bug Threaten Multi-Signature Wallet Operational Methods with Fake RawTX

Cryptovenom: The Cryptography Swiss Army Knife

CVE-2025-4138 - Python Arbitrary file write outside extraction directory

Arbitrary file read controller based on CVE-2021-29447

CVE-2026-56782 — Gorse <0.5.10 unauthenticated DB dump/restore (admin_api_key fail-open). Lab + PoC, verified e2e.