#1Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.
Kitploit recommended

A Java application intentionally vulnerable to CVE-2021-44228

CTF challenge demonstrating CVE-2024-4577 PHP CGI argument injection, with vulnerable app, attack scripts, and Kubernetes/Docker deployment for…

Intentionally vulnerable PHP app with Nginx/PHP-FPM setup for reproducing CVE-2019-11043, including Docker and Kubernetes deployment,…

F5 BIG-IP iControl REST vulnerability RCE exploit with Java including a testing LAB

搭建漏洞利用测试环境

Achat 0.150 beta7 - Remote Buffer Overflow Rewrite for python3 for the PNPT course.

CTF challenge demonstrating Django ORM filter injection (CVE-2025-64459) with auth bypass and product filter bypass exploits, including deployment…

This contains single-file exploit for ProFTPd 1.3.5 mod_copy (CVE-2015-3306) vulnerability, especially for TryHackMe Kenobi Lab.

A poc for Bootstrap XSS(CVE-2024-6485、CVE-2016-10735、CVE-2019-8331、CVE-2018-14040)

SQL injection in QuerySet.annotate(), aggregate(), and extra()

SQL injection via unsanitized QuerySet.order_by() input

Proof-of-concept exploit for CVE-2021-44228 (Log4Shell) that automates LDAP and HTTP servers to deliver a reverse shell payload to a vulnerable Java…

vulnerable-nextjs-14-CVE-2025-29927

Proof of concept of CVE-2017-5638 including the whole setup of the Apache vulnerable server

JBoss CVE-2017-12149 (Insecure Deserialization - RCE) Exploitation Lab.

CVE-2025-55183 POC

POC for CVE-2025-54918 and a technical demonstration.

Study and exploit the vulnerability CVE-2022-21661 that allows SQL Injections through plugins POST requests to WordPress versions below 5.8.3.