Community Hub

📚 Writeups, Bug Bounty Reports & Resources

The latest community writeups, spoiler-safe hints, freshly launched labs, auto-gathered bug bounty reports from around the web, and a curated toolbox — one place, every link.

🐞 Bug Bounty Reports

Auto-gathered from public writeup feeds · refreshed every 6h

CVE-2024-45195: Apache OFBiz Unauthenticated Remote Code Execution (Fixed)
RCEForced browsingBroken authorization
Ryan Emmons · Apache OFBiz · 2024-09-05
Vulnerabilities in Open Source C2 Frameworks
RCEOS command injectionAuthentication bypassArbitrary file download
Laurence Tennant · Bishop Fox (Sliver), Havoc · 2024-09-18
Living off the VPN — Exploring VPN Post-Exploitation Techniques
Hardcoded secretsCredentials sent over unencrypted channel
Ori David (@oridavid123) · Ivanti (Connect Secure), Fortinet (Fortigate VPN) · 2024-08-07
Angular-ing for AuthZ, Problematic anti-patterns in Single Sign On Systems
SSOAuthentication bypass
Traceable ASPEN · - · 2024-03-05
Pwn2Own Miami: Aveva Edge Arbitrary DLL Loading Vulnerability
Arbitrary DLL loadingRCE
Piffd0s (@piffd0s) · AVEVA · 2024-08-01
When Certificates Fail: A Story of Bypassed MFA in Remote Access
2FA / MFA bypassCitrix
Michael Eder (@michael_eder_) · - · 2024-09-09
Data Theft in Salesforce: Manipulating Public Links
SOQL injection
Nitay Bachrach · Salesforce · 2024-09-16
Logic Flaw: I Can Block You from Accessing Your Own Account
Logic flaw
Hashim Amin · - · 2024-09-13
How to Bypass Golang SSL Verification
SSL verification bypassSecurity code review
Michael Pasternak · - · 2024-07-15
Plug Security Holes in React Apps That Can Lead to API Exploitation
SSOJWTBroken authenticationMissing authentication
Eaton Z. (@XeEaton) · Siemens · 2024-07-31
Attacking PowerShell CLIXML Deserialization
Insecure deserializationRCE
Alexander Andersson · Microsoft · 2024-09-13
Microsoft Windows MSI Installer - Repair to SYSTEM - A detailed journey
Local Privilege Escalation
Michael Baer · Microsoft (Windows) · 2024-09-12
Unmasking Harmful Content in a Medical Chatbot: A Red Team Perspective
AILLM JailbreakChatbot
William Wallace (@phyr3wall) · - · 2024-09-05
Spip Preauth RCE 2024: Part 2, A Big Upload
RCEFile uploadSecurity code review
Laluka (@TheLaluka) · SPIP · 2024-09-04
[2,500$ Bug Bounty Write-Up] Remote Code Execution (RCE) via unclaimed Node package
RCEDependency confusion 💰 2,500
Fuleki Ioan · - · 2024-09-18
Interesting Story of an Account Takeover Vulnerability
Account takeoverHost header injection 💰 2,000
Deepanshu (@golu_369) · - · 2024-09-12
Revival Hijack – PyPI hijack technique exploited in the wild, puts 22K packages at risk
CI/CDSupply chain attack
Andrey Polkovnichenko, Brian Moussalli · PyPI · 2024-09-04
Directory Traversal, SQL Injection and Server-Side Request Forgery
Path traversalSQL injectionSSRF
Chris McCurley (@chrisrmccurley) · Sage · 2024-09-10
Getting code execution on Veeam through CVE-2023-27532
RCEInsecure deserializationSecurity code review
Alain Mowat (@plopz0r) · Veeam · 2024-09-10
Microsoft Copilot: From Prompt Injection to Exfiltration of Personal Information
AILLMPrompt injection
Johann Rehberger (wunderwuzzi23) · GitHub (Copilot) · 2024-08-26
Government Emails at Risk: Critical Cross-Site Scripting Vulnerability in Roundcube Webmail
XSSSecurity code review
Oskar Zeino-Mahmalat · Roundcube · 2024-08-05
We Spent $20 To Achieve RCE And Accidentally Became The Admins Of .MOBI
RCETLD hacking
watchTowr (@watchtowrcyber) · - · 2024-09-11
Zero-Click Calendar invite — Critical zero-click vulnerability chain in macOS
RCEArbitrary file writeArbitrary file deleteTCC bypass
Mikko Kenttälä (@Turmio_) · Apple (macOS) · 2024-09-13
Escalating From Reader To Contributor In Azure API Management
Privilege escalation
Christian Håland · Microsoft (Azure) · 2024-09-13
Hijacking SQL Server Credentials using Agent Jobs for Domain Privilege Escalation
Privilege escalation
Scott Sutherland · - · 2024-09-10
Recursive Amplification Attacks: Botnet-as-a-Service
DDoS
Ben Kofman, Ryan Grunsten · - · 2024-07-24
Self-XSS to ATO via Site Features
Self-XSSAccount takeover
Hossein Shourabi (@hoseinshurabi) · - · 2024-09-08
$15k RCE Through Monitoring Debug Mode
RCELFIDebug mode enabled 💰 15,000
Omar (@0x0ld) · - · 2024-08-28
Back To School - Exploiting A Remote Code Execution Vulnerability In Moodle
RCESecurity code review
RedTeam Pentesting (@RedTeamPT) · Moodle · 2024-08-27
How I Got $250 For My Second Bug on HackerOne
OAuthSession expiration issue 💰 250
Likith Teki · - · 2024-09-01
Zomatoooo! IDOR in Saved Payments
IDOR
Prateek Srivastava · Zomato · 2024-09-04
CSRF Bypass Using Domain Confusion Leads To ATO
CSRFAccount takeover 💰 4,000
Osama Aly · - · 2024-08-28
P3 (Medium) : How I Gain Access To NASA's Internal Workspace?!
Information disclosure
Sri Shavin Kumar · NASA · 2024-09-03
IIS welcome page to source code review to LFI!
LFIBlind SSRFSecurity code review
Omar Ahmed (@spaceboy2O) · - · 2024-09-01
WordPress GiveWP POP to RCE (CVE-2024-5932)
RCEPHP pop chainPHP object injectionSecurity code review
Julien Ahrens (@MrTuxracer) · Wordfence · 2024-08-26
The Hunt for XXE to LFI: How I Uncovered CVE-2019–9670 in a Bug Bounty Program
XXELFIComponents with known vulnerabilities
Karthikeyan.V (@karthithehacker) · - · 2024-08-31
Bypassing CSP via URL Parser Confusions : XSS on Netlify’s Image CDN
XSSCSP bypass
Sudhanshu Rajbhar (@sudhanshur705) · Netlify · 2024-09-01
Basic HTTP Authentication Risk: Uncovering pyspider Vulnerabilities
Reflected XSSCSRFSecurity code review
Yaniv Nizry (@YNizry) · pyspider · 2024-09-02
Analysis of CVE-2024-43044 — From file read to RCE in Jenkins through agents
RCEArbitrary file read
Gabriel Quadros (@gqsilva), Ricardo Silva (@rick2600) · Jenkins · 2024-08-29
CVE-2024-37079:
Integer underflowBuffer OverflowMemory corruption
Grigory Dorodnov, Guy Lederfein (@glederfein) · VMware · 2024-08-28
Breaking Down Barriers: Exploiting Pre-Auth SQL Injection In WhatsUp Gold - CVE-2024-6670
SQL injectionReverse engineeringSecurity code review
Sina Kheirkhah (@SinSinology) · Progress (WhatsUp Gold) · 2024-08-30
Key and E: A Pentester’s Tale on How a Photo Opened Real Doors
Red team
Patricia Gagnon-Renaud · - · 2024-08-30
Ghost In The Ppl Part 1: Byovdll
Use-After-FreeMemory corruptionLSA Protection bypass
Clément Labro (@itm4n) · - · 2024-09-02
3CX Phone System Local Privilege Escalation Vulnerability
Local Privilege EscalationArbitrary file read
Adam Crosser · 3CX · 2024-08-28
Null Byte on Steroids
Null-Byte injectionAccount takeoverPassword resetSQL injection
Omar (@0x0ld) · - · 2024-02-06
$4,998 Bounty Awarded and 100,000 WordPress Sites Protected Against Unauthenticated Remote Code Execution Vulnerability Patched in GiveWP WordPress Plugin
RCEPHP pop chainPHP object injectionSecurity code review 💰 4,998
Villu Orav (@villu164) · Wordfence · 2024-08-19
4 exploits, 1 bug: exploiting cve-2024-20017 4 different ways
RCEBuffer OverflowMemory corruption
hyper (@hyprdude) · MediaTek · 2024-08-30
[$500] How I was able to give verification badge to any YouTube channel and bypass needed requirements
Parameter tampering 💰 500
Vojtech Cekal · Google (Youtube) · 2024-08-27
A Story About How I Found XSS in ASUS
XSS
Karthikeyan.V (@karthithehacker) · Asus · 2024-09-01
Bypassing airport security via SQL injection
SQL injection
Ian Carroll (@iangcarroll) · - · 2024-08-29
Double Agent: Exploiting Pass-through Authentication Credential Validation in Azure AD
CloudPrivilege escalationLateral movement
Ilan Kalendarov (@IKalendarov), Elad Beber · Microsoft (Entra ID / Azure AD) · 2024-08-15
Self XSS + Login CSRF + OAuth = Account Takeover
Account takeoverOAuthLogin CSRFSelf-XSS
LS (@Loupreme_) · - · 2024-07-02
How I got $24000 Bounty from a Log4j RCE in Apple App Store.
RCEComponents with known vulnerabilities 💰 24,000
Mehar huzaifa (@Hunter_Huzaifa_) · Apple · 2024-08-25
Addressed AWS defaults risks: OIDC, Terraform and Anonymous to AdministratorAccess
CloudOIDCTerraformPrivilege escalation
Eduard Agavriloae (@saw_your_packet) · AWS · 2024-08-15
How I Got Bugs From Google Dorks
Information disclosure
Chandan das · - · 2024-08-25
How I can easily get four P1 at NASA using Simple Google Dorking.
Information disclosure
Francesco Topol / k4tedu · NASA · 2024-08-23

📝 Community Writeups

Full writeups unlock on each machine page after you root it

Capsule A
by suraj_pun_magar · 2026-07-21
Porthaven A
by suraj_pun_magar · 2026-07-21
Inkblot B
by rahatsahriarrafi · 2026-07-20
Axiom B
by rahatsahriarrafi · 2026-07-20
Meridian Hub A
by rahatsahriarrafi · 2026-07-20
Irongrep A
by suraj_pun_magar · 2026-07-19
Vault Keygen B
by suraj_pun_magar · 2026-07-18
API Users A
by suraj_pun_magar · 2026-07-16
Driftsync C
by tjat · 2026-06-28
Axferia D
by tjat · 2026-06-28
Capsule A
by lazacant · 2026-06-26
Axiom B
by nasim · 2026-06-26
Shellcast B
by nasim · 2026-06-26
Breakout B
by lazacant · 2026-06-25
Darkpulse A
by fearlesssec · 2026-06-23
Switchboard FTP C
by suraj_pun_magar · 2026-06-23
CIRT Gateway A
by suraj_pun_magar · 2026-06-23
Blindspot B
by lazacant · 2026-06-23
GraphLeak B
by mahnoor27 · 2026-06-23
Blindspot A
by suraj_pun_magar · 2026-06-23
Driftsync B
by suraj_pun_magar · 2026-06-23
Shellcast A
by lazacant · 2026-06-22
Foxhole A
by lazacant · 2026-06-22
Rootbase A
by suraj_pun_magar · 2026-06-21
Shellcast A
by 0xrobiul · 2026-06-20
Retrogate A
by fearlesssec · 2026-06-18
Tempest A
by fearlesssec · 2026-06-18
Shapeshifter C
by davidkarpinski1 · 2026-06-18
Listeria B
by fearlesssec · 2026-06-17
VoltCore B
by davidkarpinski1 · 2026-06-17

💡 Latest Hints

Spoiler-safe nudges submitted by the community

Inkblot Privilege Escalation
Check what files you can and can not write to. Think about what types of shells exist and where.
Meridian Hub Foothold
Before diving into exploits, take a moment to consider the basics of authentication hygiene. Many services ship with …
Porthaven Privilege Escalation
Once you have a foothold, don't stop at looking around your own home directory. Check what you're permitted to run wi…
Irongrep Privilege Escalation
Once you have a shell, don't go hunting for kernel exploits. Ask the system directly what commands you're permitted t…
GraphLeak Privilege Escalation
Once you're in as a low-privilege user, check what you're allowed to run as root. Some everyday tools were never desi…
VoltCore Post-Exploitation
Check what you can run with elevated privileges. That tool can execute arbitrary commands without ever giving you an …
Shellcast Privilege Escalation
Your sudo privileges deserve a closer look. Even if an older technique no longer exists, the same tool may still prov…
Neuravex Privilege Escalation
Once you're in as the low-privileged user, look at what commands you're permitted to run with elevated rights without…
Bootleak Privilege Escalation
After gaining a shell, you review which programs you can run with elevated privileges. Some trusted utilities become …
Foxhole Privilege Escalation
Once you're in as a low-privilege user, don't assume you need full sudo rights to reach root. Check exactly which com…
Under Fire Privilege Escalation
You expect a classic escalation trick, but that's not what's needed here. Your privileged capabilities are already fu…
Capsule Enumeration
Before trying to guess or crack anything, check whether every exposed service actually requires you to prove your ide…
Vuln Code Depot Privilege Escalation
Initial access is not the end of the investigation. Development leftovers and sensitive information discovered during…
SOC Runbook Privilege Escalation
You do not search for a traditional privilege escalation vulnerability. Root access is tied to successfully completin…
SIEM Station Privilege Escalation
You pay close attention to the privileged verification utility instead of assuming it only checks your work. Understa…
TokenSmith Privilege Escalation
Once you have a foothold, don't just look for files — look at what commands you're permitted to run with elevated pri…
Blacksite DB Privilege Escalation
Once you have a foothold, don't just look for files to read — look at what permissions you've already been granted. S…
CORP-WS01 General
Weak or default credentials, as well as credential reuse, are among the most common (and effective) attacks in CTFs o…
CORP-DC01 Enumeration
If you don't have much patience, use the following command to download all files recursively from a SMB share: ``…
Axiom Foothold
Consider how the web server handles incoming file uploads. Think about whether the validation relies solely on file e…

🆕 Newest Labs

Freshly launched machines

Lane: Ret2Win Premium Easy
launched 2026-08-01
Lane: Shellcode Premium Easy
launched 2026-08-01
Lane: ROP Chain Premium Medium
launched 2026-08-01
Lane: Format Str Premium Medium
launched 2026-08-01
Lane: Heap Premium Hard
launched 2026-08-01
Container Caps Premium Easy
launched 2026-07-25
Container Env Premium Easy
launched 2026-07-25
Container Mount Premium Medium
launched 2026-07-25
Container Socket Premium Medium
launched 2026-07-25
Container Escape Premium Hard
launched 2026-07-25
Vault Keygen Premium Easy
launched 2026-07-18
Vault Session Premium Easy
launched 2026-07-18

🧭 Learning Paths

Guided tracks on the platform

🎯 OSCP Path
Exam-style Linux & Windows machines, full methodology.
🧭 CPTS Path
HTB-CPTS-aligned track from recon to AD.
📝 Pentest Reporting
Write and grade real pentest plans & reports.
⚡ Project Meridian
5-machine Linux privesc series inside SolarGate Energy.
📚 All Learning Paths
Browse every guided track on the platform.

🛠 Toolbox & References

Curated offensive-security resources

GTFOBins ↗Privesc
Unix binaries abused to bypass local restrictions.
LOLBAS ↗Privesc
Living-off-the-land binaries & scripts for Windows.
HackTricks ↗Reference
Encyclopedic pentest / CTF methodology.
PayloadsAllTheThings ↗Payloads
Payloads & bypasses for every common web bug class.
PortSwigger Web Security Academy ↗Learning
Free, hands-on web vuln labs.
OWASP Testing Guide ↗Reference
Structured web app testing methodology.
OWASP Cheat Sheet Series ↗Reference
Concise defensive + offensive cheat sheets.
HackerOne Hacktivity ↗Reports
Publicly disclosed bug bounty reports.
revshells.com ↗Tooling
Reverse shell generator for every language/listener.
CyberChef ↗Tooling
Encode/decode/crypto swiss-army knife.