
CVE-2021-41773-Apache-Path-Traversal-Lab
Docker-based cybersecurity lab for studying and reproducing CVE-2021-41773 in an isolated environment.

Docker-based cybersecurity lab for studying and reproducing CVE-2021-41773 in an isolated environment.

Authenticated Arbitrary File Upload leading to Remote Code Execution Technical analysis and controlled reproduction of CVE-2026-38526 in Webkul…

Educational analysis and proof-of-concept exploit for CVE-2025-3248, a critical unauthenticated code injection vulnerability in Langflow, including…

Security research tool for PaperCut CVE-2026-81578 & CVE-2026-82078

Proof-of-concept exploits for CVE-2026-19912, CVE-2026-19913, and CVE-2026-19914, demonstrating file read and remote code execution in Kaltura,…

Docker lab demonstrating CVE-2026-17532, an unauthenticated reflected XSS in Seraphinite Accelerator that chains to RCE via admin session, with…

Proof-of-concept remote code execution exploit for CVE-2026-19874 in Metal Gear Online 3, with documentation and video demo for academic research.

Technical analysis and detection guidance for critical unrestricted file upload in Elementor Pro (CVE-2026-32475) leading to remote code execution.

wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain

Self-contained Docker lab that reproduces CVE-2025-24893, an unauthenticated SSTI-to-RCE in XWiki SolrSearch, and compares vulnerable vs patched…

Technical analysis of CVE-2025-55182 (React2Shell), covering vulnerability mechanics, root cause, controlled PoC testing, impact, and mitigation…

Advisory and Python PoC for Pluck CMS CSRF: fail-open Referer check plus double-extension upload enables webshell deployment and remote code…

Educational CVE-2018-7600 exploit project combining a Python RCE PoC, isolated Docker Drupal lab, payload research, and mitigation documentation for…

PoC exploit for CVE-2026-11104 demonstrating Jinja2 attr filter bypass in Flask, enabling server-side template injection and remote code execution.

CVE-2026-63223 PoC — CodeIgniter 4 is_image/mime_in File Upload RCE (CVSS 9.8). Unauthenticated remote code execution via unrestricted file upload…

Security Advisory: Remote Denial of Service via Reachable Assertion in URL Prefix Handling (rouille)


CVE-2026-25632 — Fix Unsafe JSON Deserialization Leading to Remote Code Execution