#1Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.
Kitploit recommended

Converted with tweaks from a metasploit module as an exercise for OSCP studying and exploit development

Simple flask application to implement an intentionally vulnerable web app to demo CVE-2023-2822.

PoC CVE-2017-5123 - LPE - Bypassing SMEP/SMAP. No KASLR

Magento Unauthorized Remote Code Execution (CVE-2016-4010)

Double Free

An activity to train analysis skills and reporting

Proof-of-concept exploit for CVE-2020-13925, a command injection vulnerability in Apache Kylin's diagnostic API, allowing remote code execution via…

Exploit for CVE-2018-6789, a heap buffer overflow in Exim's base64 decoding, achieving remote code execution via chunk overlap and ACL string…

Educational demonstration of exploiting CVE-2017-0143 (EternalBlue) on Windows 7 using Metasploit in a controlled lab environment for penetration…

Challenge based on CVE-2021-22204 where users send a malicious file to a web application to gain RCE

Python script to detect and exploit path traversal and remote code execution in Apache 2.4.50 (CVE-2021-42013), with bulk scanning and a Docker lab…

DHCP exploitation with DynoRoot (CVE-2018-1111)

A Docker-based research environment for analyzing CVE-2025-59532, a path traversal vulnerability in OpenAI Codex CLI that allows arbitrary file write…

An Ansible Role that installs the xz backdoor (CVE-2024-3094) on a Debian host and optionally installs the xzbot tool.

A simple python script for a firewall rule that blocks incoming requests based on the Spring4Shell (CVE-2022-22965) vulnerability

POC for CVE-2020-13151

CVE-2021-44228 demo webapp

Rust-based proof-of-concept exploit for CVE-2025-3248, a critical unauthenticated RCE in Langflow via /api/v1/validate/code, allowing arbitrary…