


This repository provides a learning environment to understand how an Exim RCE exploit for CVE-2018-6789 works.

An OWASP-aligned intentionally vulnerable platform for learning and testing AI, LLM, RAG, MCP, and Agentic AI security.

Exploit Windows server 2019 vulnerable to Zerologon with Garble, Chisel, wp-file-manager vulnerability (have video demo)

Full exploit chain lab and Suricata IDS detection for CVE-2022-30190 (Follina) - MSDT RCE

CVE-2025-55182 and CVE-2025-66478

We are presented with a security alert indicating the detection of the Follina (CVE-2022-30190) vulnerability. A malicious Word document triggered…

Next.js and the corrupt middleware...TRY TO HACK IT..!

Simple Java Front and Back end with bad log4j version featuring CVE-2021-44228


This experiment is destinated to demonstrate how the DNS rebinding attack works on an emulated IoT. In the setup, we have a simulated IoT device,…

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

Microsoft Office Word Rce 复现(CVE-2022-30190)

Sample docker-compose setup to show how this exploit works