


Script to demonstrate the Grafana directory traversal exploit (CVE-2021-43798).

CVE-2025-27591 – Meta below symlink following local privilege escalation (HackTheBox CTF)

CVE-2025-49113 – Roundcube ≤1.6.10 post-auth RCE via PHP object deserialization (HackTheBox CTF)

CVE-2025-24893 – XWiki SSTI unauthenticated RCE exploit (HackTheBox CTF)

Challange CVE-2020-13777

📂 Grafana LFI Exploit (CVE-2021-43798). Extracción automatizada de credenciales y configuración. 🕵️

HackTheBox — Facts (Easy/Linux) | CVE-2025-2304 + AWS S3 + SSH Key + Facter PrivEsc

HackTheBox Facts machine writeup — CVE-2025-2304, MinIO S3 enumeration, SSH key cracking, and facter privilege escalation.

Exploit CVE-2022-46363

A comprehensive collection of 12 containerized web exploitation challenges covering CVE-2023-25690, WebAuthn bypasses, HTTP/3 smuggling, and advanced…

ImageMagick Arbitrary Read Files - CVE-2022-44268

CMS Made Simple < 2.2.10 - SQL Injection . Actual working version

Reappear-CVE-2022-21449-TLS-PoC


TryHackMe CTF writeup — WordPress RCE via CVE-2024-25600, crypto miner forensics, and LockBit ransomware group identification