
wraith
Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

Hands-on workshop for learning Android kernel vulnerability analysis and exploitation, with Docker-based build environment and practical exercises.

Container escape on any docker container with healthcheck enabled via CVE-2026-31431

Python test client that sends HTTP GET requests with oversized Authorization headers to trigger header-parsing bugs like CVE-2025-4476. For…

Springboot web application accepts a name get parameter and logs its value to log4j2. Vulnerable to CVE-2021-44228.

This repository contains a proof of concept (POC) for CVE-2026-32255, a high-severity Server-Side Request Forgery (SSRF) vulnerability in Kan, an…

Full walkthrough of HTB's Reactor machine — exploit CVE-2025-55182 to gain a shell, then get root via an exposed Node.js debugger. Step-by-step with…

You didn't think I'd go and leave the blue team out, right?

Demo of the URLClassLoader JAR-swapping showing the ability to replace and exploit an already loaded JAR with inner classes

Weaponizing to get NT SYSTEM for Privileged Directory Creation Bugs with Windows Error Reporting

Here you will get awesome collection of mostly all well-known and usefull cybersecurity books from beginner level to expert for all cybersecurity…

Local Privilege Escalation in polkit's pkexec (CVE-2021-4034)


Malicious Maven pom.xml that uses "groovy-maven-plugin" to get RCE

PHP script and guide for injecting PHP webshells into JPEG images using Jhead. Used to bypass file upload filters and achieve remote command…

Security Advisory: Insufficient Access Controls Allow for Unauthorized File Downloads (Let's Chat)

CVE-2021-44228

Linux Distro for Mobile Security, Malware Analysis, and Forensics