
xz-vulnerable-honeypot
An ssh honeypot with the XZ backdoor. CVE-2024-3094

An ssh honeypot with the XZ backdoor. CVE-2024-3094

CERIO RCE CVE-2018-18852, authenticated (vendor defaults) web-based RCE as root user.


Here is the CVE-2025-65817

Cloudflare Image Resizing <= 1.5.6 | Unauthenticated Remote Code Execution

Unauthenticated Arbitrary File/Folder Deletion in Joomla Helix Ultimate (JoomShaper) <= 2.2.6 — CVE-2026-57830


CVE-2024-10220 Test repo

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass

CERIO RCE CVE-2018-18852, authenticated (vendor defaults) web-based RCE as root user.

Proof of Concept for CVE-2024-32002


A submodule for exploiting CVE-2024-32002 vulnerability.


Repo for testing CVE-2024-32002