#1Training labs, hands-on environments, and reproducible challenges for authorized, safe cybersecurity practice.
Kitploit recommended

PoC exploit for CVE-2024-4890: Sudo privilege escalation via neecdrestart (>=3.8). Ethical lab-only. Scripts in Python and C.

Demonstrating the usage of Fastrtps-DDS vulnerability CVE-2024-28231 within Ros2

Practical security research project exploiting CVE-2025-32463 to gain root access on a vulnerable sudo version. Includes write-up, PoC, and…

Educational PoC for CVE-2017-8291 (GhostButt) demonstrating remote command execution via Python PIL/Pillow EPS image processing with GhostScript…

CVE-2018-11235(PoC && Exp)

A practical chain that starts with an innocuous PDF file and ends up in a reverse shell on an AWS EC2 instance

Reproducible Docker lab for CVE-2017-20192 (Formidable Forms < 2.05.03 stored XSS) with automated PoC script for unauthenticated exploitation and…

CVE-2026-24061 - GNU InetUtils telnetd authentication bypass POC + Docker lab environment for testing

**Log4Shell PoC is a high-fidelity exploitation environment designed to replicate the CVE-2021-44228 vulnerability.** It provides a containerized…

RCE project

Proof of Concept for CVE-2025-40778: BIND 9 DNS Cache Poisoning via unsolicited Additional Section records.

Proof-of-concept exploit for CVE-2025-55182 demonstrating remote code execution in Next.js via prototype pollution. Includes a pre-configured…

Test & Analyze the CVE-2025-55182 vulnerability within Next.js Server Actions

CVE-2025-70341: Local Privilege Escalation via TOCTOU in App-Auto-Patch

PoC exploit for an authenticated RCE in CrafterCMS via Groovy sandbox bypass (CVE-2025-6384)

Python PoC for Netdata LPE (CVE-2024-32019) exploiting unsanitized PATH in ndsudo to escalate privileges to root via hijacked binaries.

Proof-of-concept exploits for CVE-2022-31199, a critical .NET deserialization RCE in Netwrix Auditor. Includes Python and PowerShell scripts, payload…

Python exploit for CVE-2025-55182 in React Server Components, injecting a shell into Next.js 16.0.6 applications. Includes a vulnerable app for…