
CVE-2026-24072-Analysis
Technical analysis of CVE-2026-24072, a local privilege escalation in Apache HTTP Server mod_rewrite, including root cause, patches, and Dockerized…

Technical analysis of CVE-2026-24072, a local privilege escalation in Apache HTTP Server mod_rewrite, including root cause, patches, and Dockerized…

A comprehensive full-lifecycle penetration testing project on Joomla 4.2.5 exploiting CVE-2023-23752 inside a Dockerized lab environment

Dockerized exploit lab and script for CVE-2026-19478, a critical unauthenticated GitLab GraphQL code injection enabling arbitrary Ruby method calls,…

Local lab simulating CVE-2026-29000 JWT/JWE authentication bypass in pac4j-jwt. Provides login, token forging, and dashboard APIs for practicing web…

Automated exploit for CVE-2022-42889 (Text4Shell) with a vulnerable Dockerized app for testing and manual exploitation guidance.

Dockerized environment to reproduce CVE-2019-16113, a directory traversal and RCE vulnerability in Bludit CMS 3.9.2, with PoC for image upload…

Dockerized honeypot for CVE-2021-44228.

A Dockerized Redash instance that is vulnerable to CVE-2021-21239

CVE-2025-1868: Advanced IP Scanner & Advanced Port Scanner NTLM Leakage HTTP Tester

Educational lab environment for CVE-2021-3156 (Baron Samedit) with a Dockerized vulnerable sudo target, exploit scaffold, canary test, root-cause…

Dockerized labs For Web Expert (OSWE) certification. Preparation for coming AWAE Training ...

Local intentionally vulnerable lab with a guided workshop and CTF challenges for practicing Git push-option RCE, unsafe deserialization,…

Dockerized vulnerable lab environment with a Python-based network monitor and dedicated exploit script, enabling hands-on exploitation, privilege…

CVE-2022-42889 dockerized sample application (Apache Commons Text RCE)

Dockerized proof-of-concept for CVE-2022-42889 (Text4Shell) with script, DNS, and URL lookup-based RCE payloads for security testing and education.

Dockerized proof-of-concept for CVE-2021-4034 (PwnKit), a local privilege escalation in polkit's pkexec, demonstrating root access from an…

Proof of Concept for CVE-2025-55182 ("React2Shell"). A fully dockerized environment demonstrating Remote Code Execution (RCE) via insecure…

Educational repository for learning CVE-2025-55182: a pre-authentication RCE in React Server Components. Includes step-by-step documentation,…