#1Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.
Kitploit recommended

Docker container with a pre-configured vulnerable Elasticsearch instance for practicing CVE-2015-1427 exploitation in a safe lab environment.
Docker container providing a vulnerable environment for CVE-2014-6271 (Shellshock) to practice exploitation and vulnerability analysis in a…

Docker container for CVE-2014-0160 (Heartbleed) vulnerability, part of the Cved framework for managing and deploying vulnerable environments for…

Docker container with a pre-configured CVE-2010-0426 environment for practicing privilege escalation exploitation in a controlled lab setting.

Step-by-step lab environment and exploit for Apache Unomi CVE-2020-13942, demonstrating MVEL expression language injection leading to remote code…

A Vagrant VM test lab to learn about CVE-2021-38647 in the Open Management Infrastructure agent (aka "omigod").

Docker-based lab demonstrating CVE-2019-9193 PostgreSQL arbitrary command execution via COPY FROM PROGRAM, with step-by-step PoC for security testing…

CVE-2021-3156 POC and Docker and Analysis write up

Detailed technical analysis and working exploit for CVE-2022-0492 Linux kernel container escape via cgroup release_agent, with step-by-step lab setup…

Detailed write-up and proof-of-concept exploit for CVE-2021-4034 (PolKit pkexec local privilege escalation), including a Docker lab environment for…

Python exploit for the CVE-2021-22204 vulnerability in Exiftool

Scripts for a lab environment demonstrating the Zerologon (CVE-2020-1472) vulnerability.

Educational exploit demonstration of CVE-2014-2323 SQL injection in lighttpd's mod_mysql_vhost, with Docker-based lab for hands-on vulnerability…

a controlled environment to test CVE-2025-55182.

Exploit PoC for CVE-2016-10033 targeting WordPress 4.6 with Docker-based vulnerable container for reverse shell without authentication.

The goal of this project is to demonstrate the log4j cve-2021-44228 exploit vulnerability in a spring-boot setup, and to show how to fix it.

Educational lab environment for researching CVE-2025-3500, an integer overflow privilege escalation exploit in Avast Antivirus 25.1.981.6 on Windows,…

Next.js Auth Bypass Lab ‐ CVE-2025-29927