#1Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.
Kitploit recommended

Exploiting Bluekeep (CVE-2019-0708) on windows 7 using metasploit (Esucational lab)
A Proof of Concept for the CVE-2021-46398 flaw exploitation

Step-by-step lab environment for exploiting CVE-2019-0232, a Tomcat CGI command injection vulnerability, with setup instructions and payload examples.

Docker container providing a vulnerable environment for CVE-2018-3811, designed for security testing and exploit practice within the Cved vulnerable…

Reproduction environment and proof-of-concept for Spring Cloud Function SpEL injection leading to remote code execution, with a runnable Java 11 demo…

Labs for Practical Malware Analysis & Triage

Jackson-databind远程代码执行漏洞(CVE-2020-8840)分析复现环境代码

Reproducible Docker lab for CVE-2024-21182 Oracle WebLogic T3/IIOP OpaqueReference JNDI injection leading to unauthenticated RCE. One-command…

Xiaomi HyperOS AVCodec Medya Framework'ündeki Use-After-Free (CVE-2025-21082) Zafiyetinin Derinlemesine Analizi, Rust Simülasyonu ve İnteraktif Web…

Educational environment for LTAT.04.022 Homework 4.

Proof-of-concept demonstrating JWT algorithm confusion in fast-jwt library. Includes vulnerable server, token forging script, and verification fix…

Offline-first dashboard for tracking CTF machines and labs, with attack lifecycle management, dynamic reverse shell builder, and embedded writeup…

A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.

Course materials for hackaday.io Ghidra training

intentionally vuln web Application Security in django

LazyWeb is a demonstration web application designed to showcase common server-side application vulnerabilities. Each vulnerability is categorized…

Python framework for performing side-channel analysis attacks (e.g., CPA) on public datasets, designed for educational use and hands-on practice in…

CVE-2025-55183 POC