#1Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.
Kitploit recommended

Proof-of-concept exploit demonstrating the Zip Slip vulnerability (CVE-2019-10743) in mholt/archiver, with a vulnerable server and Python payload for…
Python exploit for CVE-2025-55182 in React Server Components, injecting a shell into Next.js 16.0.6 applications. Includes a vulnerable app for…

Browser-based MCP CTF — OAuth token confusion and session isolation failure (CVE-2025-49596 pattern). DevTools only.

PoC éducatif pour la vulnérabilité CVE-2025-8671 (DoS HTTP/2 sur lighttpd). À utiliser uniquement en laboratoire local.

CDT Ansible playbook for deploying CVE-2017-7494 aka "SambaCry" to an Ubuntu box

CTF challenge demonstrating Django ORM filter injection (CVE-2025-64459) with auth bypass and product filter bypass exploits, including deployment…

Proof-of-concept exploit for CVE-2021-44228 (Log4Shell) that automates LDAP and HTTP servers to deliver a reverse shell payload to a vulnerable Java…

Proof-of-concept exploit for CVE-2017-1000499, a CSRF vulnerability in phpMyAdmin, demonstrating harmful database operations via crafted URLs.

Cái này dựng lên với mục đích cho ae tham khảo, chê thì đừng có xem. :))))

Docker lab for reproducing and studying CVE-2023-44487 (HTTP/2 Rapid Reset) for thesis research, providing a controlled environment for vulnerability…

Nuclei templates and Docker lab to demonstrate and validate CVE-2024-42009, a reflected XSS in Roundcube Webmail, using Out-of-Band detection via…

Educational lab environment for exploiting CVE-2022-22947 in Spring Cloud Gateway, with automated victim VM setup and attacker configuration scripts.

Exploit para escalada de privilegios en Linux basado en la vulnerabilidad Dirty Cow (CVE-2016-5195). Incluye binario, código fuente e instrucciones…

Laboratorio criado para PenTest da Vuln CVE 2024-214113(MONIKER LINK).

Spring Cloud Gateway SpEL RCE Vulnerability Environment

A Proof of Concept exploit for the PyInstaller CVE-2019-16783

This is a security assessment report regarding the EthernalBlue vulnerability (CVE-2017-0143).

CVE-2026-49468 — LiteLLM (<1.84.0) unauthenticated auth bypass via Host-header route confusion. PoC + docker lab.