
CVE-2023-23397
This script exploits CVE-2023-23397, a Zero-Day vulnerability in Microsoft Outlook, allowing the generation of malicious emails for testing and…

This script exploits CVE-2023-23397, a Zero-Day vulnerability in Microsoft Outlook, allowing the generation of malicious emails for testing and…

This script is specifically designed to solve the challenge on PentesterLab for the CVE-2013-0156 exploit

This script implements a lab automation where I exploit CVE-2021-43798 to steal user secrets and then gain privileges on a Linux system.

Docker-based lab and proof-of-concept exploit for CVE-2025-32463, a sudo chroot local privilege escalation, featuring a vulnerable Ubuntu container…

Proof-of-concept exploit for CVE-2026-31431 (Copy-Fail), a Linux kernel AF_ALG and splice() flaw enabling page cache poisoning and local privilege…

Active Directory Lab for Penetration Testing

This little script encrypts password to gpp cpassword. It useful to create vulnerable lab AD (CVE-2014-1812).

This exploit script is designed to simplify exploitation of the Erlang/OTP SSH vulnerability CVE-2025-32433 in the TryHackMe lab environment.

Automates vulnerability check for sudo versions and privilege escalation via sudoedit if exploitable, helping users test and gain root access.

This is a customized script to help solve the lab on remote code execution under the CVE-2015-3306 lab.

Self-contained Docker lab demonstrating CVE-2007-4559 (TarSlip) directory traversal via Python's tarfile module. Includes vulnerable and fixed APIs,…

Educational lab demonstrating CVE-2021-42392 RCE in H2 Database via CREATE ALIAS, with Dockerized vulnerable server and Python exploit script for…

Docker lab for reproducing CVE-2025-11262, an unauthenticated stored blind XSS in Link Whisper Free WordPress plugin. Includes vulnerable and patched…

Proof-of-Concept exploit for Apache Struts S2-052 (CVE-2017-9805) XML Deserialization Remote Code Execution. Created while solving the INE eWPTX…

Docker Compose lab reproducing CVE-2026-33626 SSRF in LMDeploy's vision-language image loader. Compares vulnerable (0.12.0) and patched (0.12.3)…

Reproducible Docker-based lab for CVE-2025-54068 in Livewire v3.6.3, including a safe PoC exploit chain script for educational vulnerability analysis.

PowerShell exploit for CVE-2024-0670, abusing CheckMK Agent MSI repair to escalate from low-privileged user to SYSTEM on Windows targets. Designed…

Local isolated reproduction lab for CVE-2026-35037, an unauthenticated SSRF vulnerability in Ech0's GET /api/website/title endpoint. Includes Docker…