HackTheBox - Nunchucks

SSTI in Nunjucks and SUID capability on Perl

HackTheBox - Tenet

Friendly PHP insecure deserialization attack and race condition