
CTF_CVE_DSP_1
Una CTF, in formato DSP-compliant, basata sulla CVE-2025-29927 di nextjs.

Una CTF, in formato DSP-compliant, basata sulla CVE-2025-29927 di nextjs.

Moment.js vuln lab

This app is the standard Asp.Net default web app with an old version of the AjaxControlToolkit, put here for those interested in CVE-2015-4670


Vuln Apache Struts with splunk

Python exploit for Chamilo Unrestricted File Upload Vuln - CVE-2023-4220

Silly Rails App to demonstrate vuln CVE-2013-0156

A simple project to check coverage of Log4J vuln CVE-2021-44228 (and related)

CVE-2026-23744 RCE + Privilege Escalation

Proof-of-concept exploit for CVE-2024-45590, demonstrating unauthenticated remote code execution in a WordPress plugin via arbitrary file upload.…

Proof Of Concept for te NetScaler Vuln


A generative test that would've caught CVE-2020-28052

Automated exploit for Chamilo command injection vulnerability (CVE-2023-34960) with auto shell upload capability for penetration testing and…

PoC for the recent critical vuln affecting OpenSSH versions < 9.3p2

Proof-of-concept exploit for CVE-2024-0582, a Linux kernel vulnerability. Leverages io_uring for buffer manipulation, KASLR leak, and privilege…

Vuln lab for CVE-2024-3408 - D-Tale Authentication Bypass & RCE

Vuln lab: MainWP Dashboard <= 3.1.2 Unauthenticated Stored XSS