
CTF-Web-Exploitation
A comprehensive collection of 12 containerized web exploitation challenges covering CVE-2023-25690, WebAuthn bypasses, HTTP/3 smuggling, and advanced…

A comprehensive collection of 12 containerized web exploitation challenges covering CVE-2023-25690, WebAuthn bypasses, HTTP/3 smuggling, and advanced…

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

The whole collection of Exploits developed by me (Hacker5preme)

A collection of selenium tests that might aid it takeover of a selenium node

JavaPayload is a collection of pure Java payloads to be used for post-exploitation from pure Java exploits or from common misconfigurations (like not…

A personal collection of Windows CVE I have turned in to exploit source, as well as a collection of payloads I've written to be used in conjunction…

Collection of exploits/POC for PrestaShop cookie vulnerabilities (CVE-2018-13784)

Collection of PoCs created for SmarterMail < Build 6985 RCE

A collection of proof-of-concept exploit scripts written by the team at Redway Security for various CVEs.

The full repo of all the labs available as part of the benchmark

Proof-of-Concept exploits for CVEs found by the team at Rhino Security Labs


PoC for CVE-2026-54350 — Budibase unauthenticated NoSQL operator injection (CVSS 10.0). Read/mass-write any document collection via a PUBLIC query.


Exploit for Mass Remote Code Execution on GPON home routers (CVE-2018-10562) obtained from Shodan.

PoC, Hunting React2Shell about CVE-2025-55182