
-CVE-2025-59528-PoC
A simple python script to exploit CVE-2025-59528, this an Authenticated RCE vulnerability in Flowise application, a popular AI tool. That is also…

A simple python script to exploit CVE-2025-59528, this an Authenticated RCE vulnerability in Flowise application, a popular AI tool. That is also…

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

This report details exploiting Trickster via an XSS in PrestaShop (CVE-2024-34716) to gain www-data access, extracting database credentials for SSH…

Exploit scripts for CVE-2015-1397 in Magento CMS, including a pre-auth exploit to gain admin credentials and a post-auth RCE module for reverse shell…

Kioptrix Level 1 writeup - CVE-2003-0201 Samba trans2open

Proof-of-concept exploit for CVE-2025-32433, enabling unauthenticated remote code execution in Erlang/OTP SSH. Includes Docker setup and reverse…

HackTheBox Facts machine writeup — CVE-2025-2304, MinIO S3 enumeration, SSH key cracking, and facter privilege escalation.

CVE-2025-24893 – XWiki SSTI unauthenticated RCE exploit (HackTheBox CTF)

CVE-2025-27591 – Meta below symlink following local privilege escalation (HackTheBox CTF)

CVE-2025-49113 – Roundcube ≤1.6.10 post-auth RCE via PHP object deserialization (HackTheBox CTF)

AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE ATT&CK…

Create your own vulnerable by design AWS penetration testing playground


Conference talk analyzing CVE-2018-8453, a Windows kernel UAF and double-free vulnerability. Covers binary diffing, exploit reproduction, heap spray,…

Proof-of-concept for unauthenticated stored XSS in SourceCodester Inventory System, demonstrating admin session hijacking via crafted registration…

Exploit for CVE-2025-32462 enabling privilege escalation by bypassing sudo host restrictions on Linux systems with affected sudo versions and…

Reproducible lab environment for CVE-2026-46716, a critical cross-tenant RCE in Nezha Monitoring via cron API authorization bypass. Includes Nuclei…

HackTheBox TwoMillion machine writeup — API abuse, command injection & CVE-2023-0386