
CVE-2021-41773-Exploit-Lab
CVE-2021-41773 Exploit Lab

CVE-2021-41773 Exploit Lab

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

Apache Tomcat PUT JSP RCE - CVE-2025-24813 - Exploit & PoC

Proof-of-concept lab for CVE-2026-48020, demonstrating a critical auth bypass in Traefik's StripPrefix middleware via path normalization. Includes…

Proof-of-concept demonstrating Alternate Data Stream (ADS) payload delivery via crafted WinRAR archives for educational research and controlled lab…


CVE-2025-55177 + CVE-2025-43300: reverse-engineering the WhatsApp-ImageIO zero-click iOS chain, with interactive labs.

A clean, interactive multi-step Local Privilege Escalation (LPE) exploit for Ubuntu OverlayFS (GameOver(lay)) that escapes the user namespace sandbox…

Local Docker lab for reproducing CVE-2026-55255, an IDOR vulnerability in Langflow's Responses API. Validates cross-user flow execution in vulnerable…

A proof-of-concept exploit for CVE-2023-43208, a remote code execution vulnerability in Mirth Connect before version 4.4.1.

Educational lab demonstrating CVE-2018-7600 (Drupalgeddon2) Remote Code Execution using a Docker-based vulnerable Drupal 7.56 environment.


Vulnerability as a service: showcasing CVS-2015-5447, a DDoS condition in the bind9 software

A PoC demonstrating CVE-2025-1913, showing how the plugin’s unsafe unserialize handling can lead to high-impact behavior in controlled environments.…

PoC for CVE-2024-36039: Demonstrating SQL Injection via PyMySQL Object-to-String serialization flaw

Proof-of-concept exploit for CVE-2026-31431 (Copy-Fail), a Linux kernel AF_ALG and splice() flaw enabling page cache poisoning and local privilege…

Buffer overflow in FreeFloat FTP Server 1.0

Learnings on how to verify if vulnerable to Ghostcat (aka CVE-2020-1938)