
dejavu
Challenge based on CVE-2021-22204 where users send a malicious file to a web application to gain RCE

Challenge based on CVE-2021-22204 where users send a malicious file to a web application to gain RCE
Mongo Vulnub Lab...Try to Hack IT.....!

HackTheBox — Facts (Easy/Linux) | CVE-2025-2304 + AWS S3 + SSH Key + Facter PrivEsc

Single-script exploit for CVE-2026-44881 that chains .git credential leakage, Portainer Git-symlink injection, arbitrary host file read, and SSH…

RedRoot is a Python-based, CLI-driven offensive security framework that brings essential red teaming tools into one unified terminal environment.…

A Docker-based research environment for analyzing CVE-2025-59532, a path traversal vulnerability in OpenAI Codex CLI that allows arbitrary file write…

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

This is a container of web applications that work with OWASP Bug Bounty for Projects

Automated steganalysis platform that detects hidden data in images using 16 parallel analyzers, bit-layer visualization, and an in-app wiki for CTF…

Evidence first autonomous web security testing for controlled, authorized targets. With reproducible labs, audit trails, reports, and XBEN…

Identify 300+ hash types instantly via CLI or web app. Prioritizes popular hashes, provides summaries, and integrates with HashCat and John the…

A happy heap editor to support your exploitation process :slightly_smiling_face:

Python proof-of-concept for CVE-2017-7269, a buffer overflow in IIS 6.0 WebDAV, enabling remote code execution on Windows Server 2003 R2.

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

WVCTF or WebVulnCTF is a gamified web platform which promotes training in pentesting and web application development security in an entertaining way.…

CTF Cheat Sheet + Writeups / Files for some of the Security CTFs that I've done

"Lavel Exploit CVE-2018-15133 is a powerful exploit that allows attackers to gain unauthorized access to vulnerable systems. This exploit was…

AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE ATT&CK…