#1Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.
Kitploit recommended

In-depth technical analysis and proof-of-concept for CVE-2017-9822, an insecure deserialization vulnerability in DotNetNuke leading to remote code…
A CVSS 10.0-rated vulnerability in the parquet-avro Java module allows remote code execution via unsafe deserialization when parsing schemas. Tracked…

Dockerized vulnerable Apache Struts application for testing CVE-2023-50164 remote code execution, with build and run instructions for security…

Hack The Box Writeup for Retired Challenge ReactOOPS - Complete solution and educational guide to CVE-2025-55182/CVE-2025-66478 (React2Shell RCE).…

A hands on lab investigating CVE-2025-39507 from a Tier 1 SOC analyst perspective. Includes log review in Microsoft Sentinel, IP analysis, real world…

CTF challenge exploiting CVE-2020-7471, a Django SQL injection vulnerability in PostgreSQL StringAgg, with Docker setup and exploit scripts.

Proof-of-concept demonstrating a use-after-free in cldflt.sys (CVE-2025-62221) that enables local privilege escalation to SYSTEM via kernel pool…

Making a lab and testing the CVE-2024-3116, a Remote Code Execution in pgadmin <=8.4

Target Code + Exploit

Docker Breakout Checker and PoC via CAP_SYS_ADMIN and via user namespaces (CVE-2022-0492)

Linux kernel hbp exploit method demo. (i.e. the degradation version of CVE-2022-42703)

vulnerable-nextjs-14-CVE-2025-29927

Security research lab for CVE-2025-55183 and CVE-2025-55184 in React Server Components

Automates vulnerability check for sudo versions and privilege escalation via sudoedit if exploitable, helping users test and gain root access.

Centreon =<19.10 Authenticated RCE

build-script for CVE-2024-46507 and CVE-2024-46508

smart contract reentrancy attack vulnerability POC

Analyzes and exploits a container escape vulnerability in legacy Docker/runc versions, demonstrating fd leakage to access the host filesystem, with…