
activemq-ids-ips-lab
IDS/IPS lab for detecting and preventing Apache ActiveMQ RCE (CVE-2023-46604) using GVM, Nmap, Snort, iptables, and UFW.

IDS/IPS lab for detecting and preventing Apache ActiveMQ RCE (CVE-2023-46604) using GVM, Nmap, Snort, iptables, and UFW.

Proof-of-concept exploit for CVE-2024-5084 (Hash Form WordPress plugin) demonstrating unauthenticated file upload to RCE. Designed for educational…

Docker container providing a vulnerable Apache Struts2 environment for CVE-2018-11776 exploitation practice and security education.

Proof-of-concept Next.js application demonstrating CVE-2025-55182 (React2Shell), a critical RCE in React Server Components, with exploit example and…

n8n RCE (CVE-2025-68613)

Proof-of-concept exploit for CVE-2025-32463, a local privilege escalation in sudo's chroot feature via malicious NSS library loading. Includes…

Dockerized proof-of-concept for CVE-2025-55182, a critical RCE in React Server Components via prototype pollution, with automated exploit scripts and…

Intentionally-vulnerable nginx 1.30.0 CVE lab images (CVE-2026-40701/42934/42945/42946) for isolated security research. Lab use only.

Proof-of-concept exploit for CVE-2025-29927 that adds x-middleware-subrequest to bypass Next.js middleware authentication checks.

Docker container providing a vulnerable environment for CVE-2019-10678, designed for security training and exploitation practice within the Cved…

Drupalgeddon3 RCE exploit lab with Docker-based vulnerable environment and Metasploit integration for hands-on CVE-2018-7602 exploitation training.

Vulnerability in HTTP Protocol Stack Enabling Remote Code Execution and Potential System Crash.

Multi-threaded exploit for CrushFTP authentication bypass (CVE-2025-54309) with race condition implementation, XML payload generation, and admin user…

Next.js Middleware Bypass Vulnerability

Create an exploit to libssh2 vulnerabulity described in CVE-2019-13115

CVE-2025-14847 explaination and lab

Simulated a real-world attack (CVE-2011-2523) against a vulnerable host, then cross-checked detection coverage against an existing…

Proof-of-concept exploit for CVE-2022-0185, a Linux kernel heap buffer overflow enabling local privilege escalation and container escape via FUSE and…