
htb-labs-nexus
Hack The Box Nexus machine write-up covering reconnaissance, Gitea credential discovery, Krayin CRM exploitation via CVE-2026-38526, initial access,…

Hack The Box Nexus machine write-up covering reconnaissance, Gitea credential discovery, Krayin CRM exploitation via CVE-2026-38526, initial access,…

Vulnerabilities in the Git node allowed authenticated users with permission to create or modify workflows to execute arbitrary system commands or…

Prestashop >= 1.7.5.0 < 1.7.8.2 - SQL injection

Proof-of-concept exploit for CVE-2021-22214, a server-side request forgery in GitLab webhooks, allowing unauthenticated attackers to make internal…

PoC for CVE-2026-4660: arbitrary file read via git checkout in hashicorp/go-getter

Exploit for CVE-2026-3854, a remote code execution vulnerability in GitHub Enterprise Server, triggered via crafted git push options. Includes…

Proof of concept for the recent CVE-2026-25232 which is a priv esc vulnerability present in Gogs.

Technical breakdown of CVE-2026-3854, a GitHub RCE via header injection in git push, explaining the vulnerability, exploitation technique, and…

Docker-based lab environment for reproducing and exploiting CVE-2026-1357, with step-by-step setup and Burp Suite exploitation guidance.

Lab environment and proof-of-concept exploit for CVE-2026-1357, a WordPress plugin vulnerability, with Docker setup and automated exploitation…

CVE-2026-0013 Android EoP PoC - Compiled artifacts for security research (Derivative of inforcqb/cve-2026-0013-exploit)

Reproducible lab for CVE-2026-10053 (GitLab npm package-registry path traversal -> arbitrary file write as git). Vulnerable 19.2.1 vs patched 19.2.2,…

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

Unauthenticated RCE exploit for Realtyna WPL < 5.3.0 that uploads a PHP webshell via hardcoded API key and executes arbitrary system commands.

An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in…

Dockerized vulnerable lab environment with a Python-based network monitor and dedicated exploit script, enabling hands-on exploitation, privilege…

Relays NegoEx/PKU2U Kerberos authentication to arbitrary targets, enabling credentialless authentication, command execution, SMB hash dumping, and…

Local proof-of-concept for CVE-2026-71557 demonstrating path traversal in go-git filesystem reference storage, including exploit logic and…