
CVE-2026-20896
Proof-of-concept lab and Python/cURL scripts demonstrating CVE-2026-20896, an authentication bypass in official Gitea Docker images via the…

Proof-of-concept lab and Python/cURL scripts demonstrating CVE-2026-20896, an authentication bypass in official Gitea Docker images via the…

Benchmark and evaluation harness testing whether LLM agents resist malicious instructions hidden in multimodal skill images, with 108 cases across…

Reproduction lab (A/B Docker) for CVE-2026-23989 — OpenCloud / ownCloud Infinite Scale public-link scope-validation bypass in Reva

Helper scripts to remaster Linux Live CD images for the purpose of creating ready to use security wargames with pre-installed vulnerabilities to…

Secure-by-default demo lab showing how container hardening (distroless images, non-root, read-only filesystem, runtime-injected secrets) can…

Proof-of-concept local privilege escalation exploit for CVE-2024-1086 targeting Linux kernels v5.14–v6.6. Achieves root shell with 99.4% success rate…

Some docker images to play with CVE-2021-41773 and CVE-2021-42013

An OWASP-aligned intentionally vulnerable platform for learning and testing AI, LLM, RAG, MCP, and Agentic AI security.

CVE-2017-8291 CTF with docker and examples

Proof-of-concept exploit for CVE-2019-14206, demonstrating arbitrary file deletion in the Adaptive Images WordPress plugin. Includes Docker lab,…

Challenge based on CVE-2021-22204 where users send a malicious file to a web application to gain RCE

Docker images and k8s YAMLs for Log4j Vulnerability POC (Log4j (CVE-2021-44228 RCE Vulnerability)

Intentionally-vulnerable nginx 1.30.0 CVE lab images (CVE-2026-40701/42934/42945/42946) for isolated security research. Lab use only.

Vulnerable docker images for CVE-2021-41773

Docker images for testing fuzzers on the Rode0day corpora