
CVE-2026-21877
Dockerized vulnerable lab environment with a Python-based network monitor and dedicated exploit script, enabling hands-on exploitation, privilege…
ctfeducationexploitation+3

Dockerized vulnerable lab environment with a Python-based network monitor and dedicated exploit script, enabling hands-on exploitation, privilege…

Lab + writeup for CVE-2026-28699: Gitea OAuth2 scope enforcement bypass via HTTP Basic auth

Automated proof-of-concept exploit for CVE-2025-29927, a Next.js middleware authorization bypass. Includes single-target and batch scanning, detailed…

Next.js Middleware Bypass Vulnerability

Next.js における認可バイパスの脆弱性 CVE-2025-29927 を再現するデモです。

Terraform-deployable vulnerable-by-design Azure lab with realistic attack paths and common misconfigurations for practicing red teaming and security…

test struts2 vulnerability CVE-2017-5638 in Mac OS X