
day06-foxcms-rce
This tiny lab simulates the core idea behind CVE-2025-29306: unsafe use of `unserialize()` on attacker-controlled input leading to remote code…

This tiny lab simulates the core idea behind CVE-2025-29306: unsafe use of `unserialize()` on attacker-controlled input leading to remote code…

hands on investigation of the heartbleed vulnerability (CVE-2014-0160).

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

My notes for CVE-2004-1561 IceCast exploitation

OSCP like CVE-2025-24893 exploit for Linux XWiki

Experimental kernel-mode EDR research project focused on explainable detection of suspicious in-memory execution patterns, producing human-readable…

A Proof of Concept for the CVE-2021-46398 flaw exploitation

An intentionally designed broken web application based on REST API.

Code for paper "ActBench: Self-Evolving Benchmark of Behavioral Safety in Cowork Agents"

Deliberately vulnerable C# API application for practicing web application exploitation and security testing. Includes Docker setup and documentation…

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

Damn Vulnerable C# Application (API)

Collection of intentionally insecure iOS and Android apps for learning mobile security testing, reverse engineering, and vulnerability analysis,…

Educational demonstration of exploiting CVE-2017-0143 (EternalBlue) on Windows 7 using Metasploit in a controlled lab environment for penetration…

Shellshock exploit + vulnerable environment

Exploit PoC for CVE-2016-10033 targeting WordPress 4.6 with Docker-based vulnerable container for reverse shell without authentication.

The repo contains a series of challenges for learning Frida for Android Exploitation.

Hands-on workshop for learning Android kernel vulnerability analysis and exploitation, with Docker-based build environment and practical exercises.