
CVE-2026-33017-FireFlow
Proof-of-concept RCE for Langflow CVE-2026-33017 using a malicious custom component to execute OS commands via build_public_tmp and retrieve output…

Proof-of-concept RCE for Langflow CVE-2026-33017 using a malicious custom component to execute OS commands via build_public_tmp and retrieve output…

CTF writeups and teaching scripts for web security, bug bounty techniques, and network forensics, with blank-value versions for active practice.

Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level…

A community‑driven cybersecurity knowledge base with 400+ notes, mind‑maps, and cheat‑sheets – built from first principles. Ideal for students, SOC…

An example C program which contains vulnerable code for common types of vulnerabilities. It can be used to show fuzzing concepts.

A collection of CTF write-ups, pentesting topics, guides and notes. Notes compiled from multiple sources and my own lab research. Topics also support…

Here you will get awesome collection of mostly all well-known and usefull cybersecurity books from beginner level to expert for all cybersecurity…

Contains all the material from the DEF CON 31 workshop "(In)direct Syscalls: A Journey from High to Low".

In this workshop session, we will extract firmware from an EV charger, dig into the firmware, and eventually emulate it so we can interact with the…

Unauthenticated arbitrary file read in Flowise (< 2.2.4) via path traversal in getFileFromStorage (storageUtils.ts). Caused by un-sanitized file path…

My write-ups from CyberDefenders' Blue Team labs, solved using Wireshark. Covers TeamCity RCE (CVE-2024-27198), XSS session hijacking, and…

From deobfuscating code.js to root, CVE-2023-0386

Generates reproducible CORE network topologies from XML scenario files for cybersecurity training and experimentation. Provides Web GUI and CLI for…

Official repository for CTFTiny

CVE-2026-0047: Missing permission check in ActivityManagerService.dumpBitmapsProto() — steal UI bitmaps from every running app with zero permissions…

KeePass CVE-2023-24055复现

Security benchmark for evaluating OpenClaw agents against adversarial execution contexts including poisoned files, injected skills, misleading tool…