#1Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.
Kitploit recommended

Proof-of-concept exploit for CVE-2017-1000117, demonstrating command injection via git clone to write arbitrary output to a web directory.

Interactive visualization of the React2Shell (CVE-2025-55182) RCE vulnerability with narrated animations for three audiences: Expert, Practitioner,…

This contains the necessary files and Docker to replicate A vulnerability in OURPHP that has a XSS Vulnerability (CVE-2023-30212)

Educational lab and PoC demonstrating CVE-2024-21413 Outlook Moniker Link attack to leak netNTLMv2 hashes via crafted HTML email.

Proof-of-concept exploit for CVE-2017-1000499, a CSRF vulnerability in phpMyAdmin, demonstrating harmful database operations via crafted URLs.

Jackson-databind远程代码执行漏洞(CVE-2020-8840)分析复现环境代码

CVE-2018-1270 表达式RCE环境

A custom Python proof-of-concept showcasing root-cause analysis and exploitation of CVE 2019-9978 (Social Warfare plugin),focusing on practical RFI…

Exploit for CVE-2021-3560 (Polkit) - Local Privilege Escalation

Linux kernel LPE practice with an NPD vulnerability

Proof-of-concept for CVE-2023-32571, demonstrating remote code execution via Dynamic Linq injection in ASP.NET applications. Includes payloads and a…

Hands-on lab for CVE-2023-6933, a PHP Object Injection vulnerability in Better Search Replace WordPress plugin, with Docker deployment, nuclei…

CVE-2023-37478 showcases how a difference in npm and pnpm install packages that could be exploited by a well crafted tar.gz packge. This repo shows a…

Cái này dựng lên với mục đích cho ae tham khảo, chê thì đừng có xem. :))))

Vulnerable docker container for Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass CVE-2023-50164

CVE-2024-1071 with Docker

Repository to install CVE-2023-7028 vulnerable Gitlab instance

Vulnerable docker container for Apache Struts 2 RCE CVE-2023-50164