
POC_CVE-2026-35037
Local isolated reproduction lab for CVE-2026-35037, an unauthenticated SSRF vulnerability in Ech0's GET /api/website/title endpoint. Includes Docker…

Local isolated reproduction lab for CVE-2026-35037, an unauthenticated SSRF vulnerability in Ech0's GET /api/website/title endpoint. Includes Docker…

This repository documents how deployment of Microsoft Defender for Endpoint on a Windows 11 device, including onboarding via local script, enabling…

Educational Linux privilege escalation exploit targeting CVE-2016-5195 (Dirty COW) to demonstrate kernel vulnerability exploitation and root access…

test struts2 vulnerability CVE-2017-5638 in Mac OS X

CVE-2018-6574: go get RCE solution for pentesterlab challenge

Proof Of Concept for the CVE-2016-10033 (PHPMailer)

Here you will get awesome collection of mostly all well-known and usefull cybersecurity books from beginner level to expert for all cybersecurity…

Threat Pursuit Virtual Machine (VM): A fully customizable, open-sourced Windows-based distribution focused on threat intelligence analysis and…

NOTICE This repository contains the public FTC SDK for the SKYSTONE (2019-2020) competition season. If you are looking for the current season's FTC…

Hands-on workshop for learning Android kernel vulnerability analysis and exploitation, with Docker-based build environment and practical exercises.

Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

beginner friendly write-up for the TryHackMe easy level module- polkit:CVE-2021-3560

Athena OS is a Arch/Nix-based distro focused on Cybersecurity. Learn, practice and enjoy with any hacking tool!

Vulnerable app with examples showing how to not use secrets

📦 Get a clean, ready-to-go Linux box in seconds.

Full walkthrough of HTB's Reactor machine — exploit CVE-2025-55182 to gain a shell, then get root via an exposed Node.js debugger. Step-by-step with…

An intentionally vulnerable webapp to get your hands dirty with CVE-2022-42889.

Springboot web application accepts a name get parameter and logs its value to log4j2. Vulnerable to CVE-2021-44228.