
research-labs
This repository contains a number of insecure self-hosted applications that allows interested security engineers to test vulnerabilities found by…

This repository contains a number of insecure self-hosted applications that allows interested security engineers to test vulnerabilities found by…

A detailed walkthrough of Billing room exploiting CVE-2023-30258 and escalating via fail2ban misconfig

Example exploitable scenarios for CVE-2024-22243 affecting the Spring framework (open redirect & SSRF).

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation

Proof-of-concept exploit for CVE-2025-49132, a critical RCE in Pterodactyl Panel (1.9.0–1.11.10), with detection and credential-dumping guidance.

Hack The Box Writeup for Retired Challenge ReactOOPS - Complete solution and educational guide to CVE-2025-55182/CVE-2025-66478 (React2Shell RCE).…

CVE-2025-6254 — Doctreat Core <= 1.6.8 — Unauthenticated Privilege Escalation

Ansible role that simulates a realistic CrushFTP CVE-2025-31161 exploitation scenario with rotating sensitive data files and automated defender…

Hack this service to prove CVE-2022–29622 is valid

Full black-box penetration test against SecOS:1 (VulnHub) — CSRF exploitation, privilege escalation via CVE-2015-1328 (OverlayFS), post-exploitation

Kirby < 3.9.6 XML External Entity exploit

Profitori 2.0.6.0 - 2.1.1.3 - Missing Authorization to Unauthenticated Privilege Escalation

Intentionally-vulnerable nginx 1.30.0 CVE lab images (CVE-2026-40701/42934/42945/42946) for isolated security research. Lab use only.

Proof-of-concept demonstrating XXE vulnerability in JetBrains Ktor < 2.3.5 via XML ContentNegotiation, with prevention guidelines and OWASP-based…

CVE-2016-15042 lab: Dockerized WordPress PoC for unauthenticated file upload in Frontend File Manager <4.0 and N‑Media Post Front‑end Form <1.1

Vuln lab: MainWP Dashboard <= 3.1.2 Unauthenticated Stored XSS

Exploitation de CVE-2022-22980