
cve-images
Intentionally-vulnerable nginx 1.30.0 CVE lab images (CVE-2026-40701/42934/42945/42946) for isolated security research. Lab use only.

Intentionally-vulnerable nginx 1.30.0 CVE lab images (CVE-2026-40701/42934/42945/42946) for isolated security research. Lab use only.

powerfull rust cve-2025-55182-scanner used for ctf & ethical purpose only

CVE-2025-66034 - fontTools varLib Arbitrary File Write → RCE PoC exploit for an Arbitrary File Write + XML Injection vulnerability in…

JWT Key Confusion PoC (CVE-2015-9235) Written for the Hack the Box challenge - Under Construction

This is a suite of tools/PoCs/exploits for cameras using the iCSee application. And yes - it can run NES games!

PoC scripts to exploit LFR (Local File Read) via PHP filters chain oracle (php://filter), especially for CTF purposes or the exploit of…

Performing multiple time-based blind injections for the same character and selecting the most frequent result significantly reduces errors and…

An interactive wizard front end for IVRE to make creating scans to the database easier.

Reproduction lab for CVE-2026-54316 (Claude Code WebFetch huggingface.co bare-hostname permission bypass / exfiltration)

An exploitation for the /dev/exynos-mem vulnerability introduced in earlier samsung phones.

Python PoC for CVE-2023-46818

Custom vulnerable VM (Ubuntu 14.04) designed for teaching multi-stage penetration testing. Features 10 interconnected challenges across Forensics,…

Exploit for the PHP 8.1.0-dev backdoor vulnerability (CVE-2021-21707)

Python3 exploit for CVE-2019-9053 (CMS Made Simple <= 2.2.9 SQLi). No deps, time-based blind SQLi → admin creds dump. HTB Writeup owned.

A self-hosted vulnerable Next.js environment running on Docker for simulating CVE-2025-55182. Built for educational security research and CTF…

For CTF's and Safe Environments.... CVE-2021-4034 Local PrivEsc.

Educational Proof-of-Concept for the Dual_EC_DRBG backdoor (CVE-2014-8610) - NIST P-256 state recovery attack demonstration