
CVE-2026-42978-PoC-Research
CVE-2026-42978 — Use-After-Free race condition in Windows Push Notifications (WpnService). Patch diff, root cause analysis, TOCTOU lab, Sysmon/ETW…

CVE-2026-42978 — Use-After-Free race condition in Windows Push Notifications (WpnService). Patch diff, root cause analysis, TOCTOU lab, Sysmon/ETW…

Proof-of-concept and lab for CVE-2026-82226, an unauthenticated PHP object injection in Tickera <= 3.6.0.2 via POST /cart/, with Docker reproduction…

SecurityTube Linux Assembly Expert x86 Exam

A fully functional DanderSpritz lab in 2 commands

Controlled penetration testing lab demonstrating CVE-2011-2523 exploitation and mitigation techniques.


CVE-2026-12940 — Langflow OSS <=1.10.1 unauthenticated RCE via MCP stdio environment-variable injection (SHELLOPTS/PS4). Author PoC + source analysis…

A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.

Struts 2 web app that is vulnerable to CVE-2017-98505 and CVE-2017-5638

Unit tests for blue teams to aid with building detections for some common macOS post exploitation methods.

CVE-2026-82286 — gpt-crawler <=1.5.1 unauthenticated arbitrary file write via outputFileName (POST /crawl). PoC + self-contained Docker lab. CVSS…

Cybersecurity lab demonstrating exploitation of CVE-2017-0144 (EternalBlue) using Metasploit against a vulnerable Windows 7 VM, achieving…

The code for personally reproducing the corresponding vulnerability

Proof-of-concept exploit for CVE-2026-2058, a SQL injection in CloudClassroom PHP Project, with automated database enumeration and data extraction.

CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).

PfSense Stored XSS lead to Arbitrary Code Execution exploit

Educational examples porting Linux kernel vulnerabilities to Rust, featuring intentionally vulnerable code and exploits for learning kernel security…