
cve-lfi-lab
A hands on lab investigating CVE-2025-39507 from a Tier 1 SOC analyst perspective. Includes log review in Microsoft Sentinel, IP analysis, real world…

A hands on lab investigating CVE-2025-39507 from a Tier 1 SOC analyst perspective. Includes log review in Microsoft Sentinel, IP analysis, real world…
The goal of this guide is very simple - to teach anyone interested in cyber security, regardless of their knowledge level, how to make the most of…

Vulnerability research write-up on CVE-2017-7921 — a critical unauthenticated auth bypass in Hikvision IP cameras/DVRs/NVRs, covering root cause,…

Multi-threaded exploit script for CVE-2024-24919 that scans a list of IP addresses and outputs results, intended for educational use.

Scanner and attack suite for hosts that forward unauthenticated packets via IPIP and GRE protocols. (CVE-2020-10136 CVE-2024-7595)

Local Go PoC demonstrating CVE-2026-72815, an X-Forwarded-For IP spoofing flaw in go-chi/chi middleware.RealIP that bypasses IP-based ACLs, with a…

CVE-2026-33693: SSRF via 0.0.0.0 Bypass in activitypub-federation-rust v4_is_invalid() (CVSS 6.5 Moderate)

Ruby on Rails Web Console Exploit (CVE-2015-3224)

Documents CP PLUS EZ-P21 IP camera CVEs: arbitrary code execution via debug feature and improper authentication of HTTP endpoints, with responsible…

Python PoC for CVE-2021-34527 (PrintNightmare) that sends a hard-coded SMB exploit payload to a target IP and port for educational demonstration.

Proof-of-concept exploit for CVE-2024-24919, an unauthenticated file read in Check Point Security Gateways; scans single or multiple IP targets and…

Script to install prerequisites for deploying GOAD on Ubuntu Linux 22.04

Simple shell script to automatically request new Tor identity at configurable intervals for IP rotation.

Python-based DDoS attack tool for flooding targets with traffic via IP and port specification. Designed for educational stress-testing and network…

This function combines all the above functions and takes necessary information from the user to change the IP and MAC address, start the responder…

Sensitive info disclosure via info API in PictShare < 3.7.1 (CWE-522). PoC + advisory writeup.

Proof-of-concept exploit for CVE-2025-49132, a path traversal vulnerability in Pterodactyl panel. Forges session cookies using exposed Redis server…

Proof-of-concept exploit for CVE-2024-45590, demonstrating unauthenticated remote code execution in a WordPress plugin via arbitrary file upload.…