#1Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.
Kitploit recommended

Educational repository for researching CVE-2026-83548 and CVE-2026-83549, providing proof-of-concept resources and guidance for authorized security…
Reproducible Docker lab + raw-socket exploit for CVE-2015-3306 (ProFTPD mod_copy pre-auth arbitrary file copy) — a patch-diffing learning exercise

Proof-of-concept for CVE-2026-86218, a pre-auth remote code execution in N-central, intended for authorized security testing and educational research…

Demonstration of the expression language (EL) injection vulnerability CVE-2018-14667 using the photoalbum lab under Jboss application server

ActiveMQ CVE-2015-5254 模拟靶场 - 用于 CVE 测试评测和 SCA 扫描演示

Local privilege escalation exploit for CVE-2026-31431, a Linux kernel AF_ALG + splice page-cache overwrite. Includes PoC, BPFtrace detection script,…

Educational repository analyzing CVE-2026-31431, providing lab-based testing guidance and defensive awareness for authorized security research.

Educational lab demonstrating a deserialization vulnerability in Microsoft SharePoint that enables remote code execution, with a hands-on…

Local Docker lab and timing-based proof-of-concept for CVE-2026-42208, a pre-auth SQL injection in LiteLLM Proxy, demonstrating vulnerable vs patched…

Reproducible lab for CVE-2026-33017, an unauthenticated RCE in Langflow. Includes a Dockerized vulnerable service and a least-harm PoC that…

Reproduces CVE-2026-1581, an unauthenticated time-based SQL injection in wpForo Forum <=2.4.14, with a Docker lab and PoC to demonstrate the…

Proof-of-concept exploit for CVE-2025-8625 targeting WordPress, with Docker-based isolated lab environment and demonstration web shell for…

Educational lab environment demonstrating CVE-2025-49844 (RediShell) in Redis. Includes Docker setup, exploit PoC script, and security…

Simulation environment for CVE-2026-24841, providing a realistic vulnerable setup for security testing and educational purposes, especially for…

Educational lab environment with a proof-of-concept exploit for CVE-2025-49844 (RediShell), a critical use-after-free in Redis Lua interpreter,…

A vulnerable web app for log4j2 RCE(CVE-2021-44228) exploit test.

Exploit and analysis of CVE-2023-3460, a critical privilege escalation in the Ultimate Member WordPress plugin, with reproduction environment and…

Step-by-step exploit harness and proof-of-concept for CVE-2026-25526 in Jinjava, demonstrating file read, file creation, and info disclosure with…