
CVE-2026-48282-coldfusion-rds-detection
Laboratory validation of CVE-2026-48282 in Adobe ColdFusion RDS with arbitrary CFM file write, code execution, auditd/PCAP evidence, event timeline…

Laboratory validation of CVE-2026-48282 in Adobe ColdFusion RDS with arbitrary CFM file write, code execution, auditd/PCAP evidence, event timeline…

Blind noSQL injection case study lab based on CVE-2018-3783

Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).

CVE-2026-34038: Authenticated Remote Command Injection in Coolify

CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling…

Apache Solr RCE CVE-2020-13957

Educational Docker-based lab demonstrating CVE-2021-41773 path traversal exploit against Apache httpd 2.4.49, with curl-based exploitation commands.

Investigating CVE-2022-36804

CVE-2026-39987

This container was made to explain and demonstrate how CVE-2019-15813 (Sentrifugo works)

CVE-2026-22243 - EGroupware has SQL Injection in Nextmatch Filter Processing

A comprehensive full-lifecycle penetration testing project on Joomla 4.2.5 exploiting CVE-2023-23752 inside a Dockerized lab environment

CVE-2026-23500 - OS Command Injection (RCE) via MAIN_ODT_AS_PDF configuration in Dolibarr

Docker-based lab environment to verify and exploit two unauthenticated API vulnerabilities (CVE-2026-42221, CVE-2026-42238) in nginx-ui, with patched…

Critical unauthenticated kill chain leading to full RCE in FlowiseAI (CVE-2025-58434 + CVE-2025-59528)

CVE-2021-44228 漏洞复现完整记录(含环境搭建、触发验证)

Sequelize Sql Injection 취약점 구현

CVE-2019-11043 PHP远程代码执行