
CVE-2014-6271
Python exploit for CVE-2014-6271 (ShellShock) enabling remote code execution via crafted environment variables in GNU Bash, targeting web servers and…

Python exploit for CVE-2014-6271 (ShellShock) enabling remote code execution via crafted environment variables in GNU Bash, targeting web servers and…

Deliberately vulnerable client-server application for learning penetration testing of non-HTTP thick clients. Includes challenges for SQL injection,…

FastJsonAutoTypeBypass

CVE-2023-20198 PoC (!)

Docker-based lab environment and proof-of-concept scripts for exploiting CVE-2020-10560, an arbitrary file read vulnerability in OSSN. Includes PHP…


Proof-of-concept exploit for CVE-2025-30065 demonstrating remote class instantiation and SSRF via malicious Parquet files in Java applications.

Dockerized vulnerable lab demonstrating CVE-2024-2083 in ZenML, a path traversal vulnerability in the step logs API allowing arbitrary file read.

Browser demo: EJS template injection (CVE-2022-29078) with Seal Security remediation

Demonstrates exploitation of CVE-2017-8046 in a Spring Boot application, including a SpEL injection payload and dependency-check verification for…

docker for CVE-2022-42889

Browser demo: EJS template injection (CVE-2022-29078) with Seal Security remediation

Buildpack providing a workaround for CVE-2021-44228 (Log4j RCE exploit)

Demo to show how Log4Shell / CVE-2021-44228 vulnerability works

This lab demonstrates the exploitation of CVE-2024-24945, a heap corruption vulnerability affecting NGINX. The objective was to understand how memory…

Sample docker-compose setup to show how this exploit works

PoC Authentication Bypass to RCE to Exploit CVE-2025-31161

PoC for login with password hash in STARFACE