
SOC274-Palo-Alto-Networks-PAN-OS-Command-Injection-Vulnerability-Exploitation-CVE-2024-3400
SOC lab exercise for analyzing and responding to Palo Alto Networks PAN-OS command injection vulnerability (CVE-2024-3400) with step-by-step incident…

SOC lab exercise for analyzing and responding to Palo Alto Networks PAN-OS command injection vulnerability (CVE-2024-3400) with step-by-step incident…

A hands-on lab for understanding and exploiting CVE-2025-55182 (React2Shell) - Remote Code Execution in React Server Components

Sets up a Dockerized environment to reproduce and analyze CVE-2024-47167, a vulnerability in Gradio 4.40.0, with an internal HTTP server and…

Local lab for understanding CVE-2025-55182 RCE in React Server Components/Next.js. Includes a deliberately vulnerable app and optional scanner helper…

Proof-of-concept lab for CVE-2017-5941 node-serialize untrusted deserialization RCE. Includes POST and cookie-based exploit vectors with Docker…

Simple Java Front and Back end with bad log4j version featuring CVE-2021-44228

Educational PoC for Dirty COW (CVE-2016-5195) with logging, ptrace fallback, and binary payload support.

Insecure TeamCity CI environment for hands-on penetration testing training: reconnaissance, credential theft, privilege escalation, and lateral…

Challenge based on CVE-2021-22204 where users send a malicious file to a web application to gain RCE

Sample Spring Boot web application vulnerable to Log4j2 CVE-2021-45046, demonstrating JNDI injection and infinite loop exploitation for educational…

Security documentation and lab companion for the polkit pkexec local privilege escalation, with a TryHackMe room for hands-on exploitation practice.

Sample Spring Boot application intentionally vulnerable to Log4j2 CVE-2021-45105 for practicing exploitation and understanding infinite loop…

Detecting CVE-2022-26134 using Nuclei

CVE-2026-25632 — Fix Unsafe JSON Deserialization Leading to Remote Code Execution

Some labs looking at the xz backdoor vulnerability (CVE-2024-3094)

Hands-on lab for CVE-2026-40072 — SSRF vulnerability in web3.py via CCIP Read (EIP-3668)

Small CTF challenges running on Docker

PoC for CVE-2026-66066 in Ruby on Rails