#1Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.
Kitploit recommended

To solve CTFS.me problem
Educational demo of a Server-Side Request Forgery (SSRF) vulnerability in Next.js (CVE-2024-34351), with step-by-step exploitation and mitigation…

CVE-2025-49144 * Notepad++ v8.8.1 * SYSTEM-level POC

The POC and Lab setup documentation of CVE 2021 41773

Automated local privilege escalation exploit for CVE-2023-22809 (sudoedit -e) that checks sudo permissions and modifies sudoers to gain a root shell.…

Exploit for Apache 2.4.49/2.4.50 path traversal and RCE (CVE-2021-42013). Includes Docker setup and script to test path traversal, execute commands,…

Proof-of-concept exploit for CVE-2021-3560, a Polkit local privilege escalation vulnerability, allowing unprivileged users to gain root access.…

CVE-2020-0796 explanation and researching vulnerability for term porject CENG325

Proof-of-concept exploit for CVE-2023-30212, an XSS vulnerability in Ourphp 7.2.0, including Docker setup and payload demonstration.

Reproduction script for CVE-2025-48384, a git clone RCE via carriage return in submodule paths, demonstrating the vulnerability and providing a local…

PoC for CVE-2016-1000027

Study on CVE-2020-13401 vulnerability of containers in dockers older than 19.03.11

A Docker image vulnerable to CVE-2020-7246.

Log4Shell (CVE-2021-44228) PoC

A one-stop repo/ information hub for all log4j vulnerability-related information.

A docker container vulnerable to Shellshock - CVE-2014-6271

vsftpd 2.0.5 - 'CWD' (Authenticated) Remote Memory Consumption

Docker images and k8s YAMLs for Log4j Vulnerability POC (Log4j (CVE-2021-44228 RCE Vulnerability)