
CVE-2021-41773-Apache-Path-Traversal-Lab
Docker-based cybersecurity lab for studying and reproducing CVE-2021-41773 in an isolated environment.

Docker-based cybersecurity lab for studying and reproducing CVE-2021-41773 in an isolated environment.

Proof-of-concept for CVE-2026-86218, a pre-auth remote code execution in N-central, intended for authorized security testing and educational research…

Reproducible Docker-based proof-of-concept for CVE-2026-19949, a second-order SQL injection in All-in-One WP Migration <= 7.109 that leaks the…

Docker lab environment with PoC exploit and checker for CVE-2026-20253, a pre-auth RCE in Splunk Enterprise via the PostgreSQL sidecar service.

PoC exploit and technical analysis for CVE-2024-38063 in the Windows IPv6 stack, built with Python and Scapy

Docker lab + Python exploit for CVE-2024-7804 (PyTorch torch.distributed.rpc unsafe pickle deserialization RCE, CWE-502, torch <= 2.3.1)

Proof-of-concept exploit for CVE-2026-56121, an unauthenticated RCE in Feast's registry gRPC server via unsafe dill deserialization. Includes a…

Proof-of-concept exploit for CVE-2026-9198, an unauthenticated RCE in IBM Langflow OSS, chaining auto_login and validate/code endpoints. Includes a…

Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078

Writeup + CVE analysis + countermeasures for the Hacktivity 'Vulnerabilities, Exploits, and Remote Access Payloads' lab (netcat shells, Metasploit,…

Docker-based CTF lab demonstrating CVE-2024-4577 PHP-CGI argument injection leading to RCE. Includes vulnerable PHP 5.4.1 CGI, exploit scripts, and…

Docker lab demonstrating CVE-2026-17532, an unauthenticated reflected XSS in Seraphinite Accelerator that chains to RCE via admin session, with…

Documented penetration test on an isolated Metasploitable2 VM using Metasploit and Nmap, covering remote exploitation, privilege escalation, and…

Docker-based lab environment to reproduce and test CVE-2022-42889 (Text4Shell) remote code execution vulnerability in Apache Commons Text.

wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain

Self-contained Docker lab that reproduces CVE-2025-24893, an unauthenticated SSTI-to-RCE in XWiki SolrSearch, and compares vulnerable vs patched…


Exploits a critical pre-auth heap use-after-free in Exim via TLS close_notify to gain remote root; includes a GDB lab harness and Nuclei detection…