
log4j-CVE-2021-44228
Apache Log4j Zero Day Vulnerability aka Log4Shell aka CVE-2021-44228

Apache Log4j Zero Day Vulnerability aka Log4Shell aka CVE-2021-44228

Kubernetes Security Training Platform - focusing on security mitigation

Web application security assessment of DVWA using OWASP ZAP — vulnerability scanning, RCE (CVE-2012-1823) analysis, and remediation report.

CVE-2022-31626, CVE-2024-2961, CVE-2019-6977, PHP security research

Educational lab and proof-of-concept materials for a specific CVE, providing sandboxed scripts and templates for vulnerability research, authorized…

CVE-2025-14847 (MongoBleed) scanner and exploit tool. Unauthenticated MongoDB heap memory leak via zlib decompression. Detection, memory extraction,…

CVE-2025-54424: 1Panel TLS client cert bypass enables RCE via forged CN 'panel_client' using a bundled scanning and exploitation tool. Affected: <=…

VAPT report for vsFTPd 2.3.4 backdoor CVE-2011-2523, covering Nmap vulnerability scanning, Metasploit exploitation, post-exploitation root access,…

Test target: fresh Laravel 12 app with Livewire pinned to vulnerable 3.6.3 (CVE-2025-54068) for recon scanning

Blue Team lab focused on analyzing Apache web access logs to detect directory brute forcing and web scanning activity.

Python exploit script for Apache 2.4.50 CVE-2021-42013 path traversal and remote code execution, with bulk scanning and Docker lab for hands-on…

Python script to detect and exploit path traversal and remote code execution in Apache 2.4.50 (CVE-2021-42013), with bulk scanning and a Docker lab…

Hands-on pentest project using Kali Linux vs Metasploitable2. Includes full workflow: Nmap scanning, enumeration, Metasploit exploitation (Samba…

Automated proof-of-concept exploit for CVE-2025-29927, a Next.js middleware authorization bypass. Includes single-target and batch scanning, detailed…

A hands-on vulnerability assessment and exploitation of a Windows 7 VM using the EternalBlue (CVE-2017-0143) exploit. Includes scanning, exploitation…

Educational lab demonstrating Shellshock (CVE-2014-6271) exploitation using Metasploit against Metasploitable 2, including scanning, exploitation,…

Python script to detect and exploit CVE-2021-42013 path traversal and remote code execution in Apache 2.4.50, with bulk scanning and a Docker lab for…

Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp…