
not-slithering-anywhere
The Python Version of our Not Go-ing Anywhere Vulnerable Application

The Python Version of our Not Go-ing Anywhere Vulnerable Application

One-Day POC | GeoServer Unauthenticated SQL injection to complete RCE

Intentionally vulnerable Golang programs exposing web, gRPC, and database/sql flaws for security training, vulnerability discovery, and remediation…

An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in…

Automated exploit for DataEase: 4-vulnerability chain (auth bypass, JDBC blocklist bypass, SQL injection, Java deserialization) achieving…

The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how…

Proof-of-concept exploit for CVE-2025-21333, a heap-based buffer overflow in Hyper-V's vkrnlintvsp.sys leading to local privilege escalation via I/O…

Proof-of-concept exploit for CVE-2018-5740, a denial-of-service vulnerability in BIND DNS server triggered by a crafted DNAME query, with…

Proof of Concept for CVE-2025-40778: BIND 9 DNS Cache Poisoning via unsolicited Additional Section records.

Log4Shell (CVE-2021-44228) docker lab

F5 BIG-IP iControl REST vulnerability RCE exploit with Java including a testing LAB

Controlled NGINX HTTP/2 frame injection lab for CVE-2026-42926 patch validation and defensive research

This is a security assessment report regarding the EthernalBlue vulnerability (CVE-2017-0143).

Demonstrates a real-world zero-trust bypass by exploiting BIND CVE-2025-40775 to disrupt DNS, break secret rotation, and expose static credentials in…

Kirby < 3.9.6 XML External Entity exploit

Demo-ing CVE-2017-1000253 in a container

🚨 Just completed an incident report on Event ID 217: Apache OFBiz Auth Bypass and Code Injection 0-Day (CVE-2023-51467). This critical vulnerability…

Kurukshetra - A framework for teaching secure coding by means of interactive problem solving.