
awesome-cyber-skills
A curated list of hacking environments where you can train your cyber skills legally and safely

A curated list of hacking environments where you can train your cyber skills legally and safely

Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.

Fastjson 1.2.83 RCE 靶场环境 (CVE-2026-16723)

Local privilege escalation exploit for CVE-2023-52927, a Use-After-Free vulnerability in the Linux kernel netfilter subsystem, with a KASAN trigger…

Docker lab for reproducing CVE-2025-11262, an unauthenticated stored blind XSS in Link Whisper Free WordPress plugin. Includes vulnerable and patched…

Educational standalone JavaScript implementation of the public exploit for CVE-2016-9079 (Firefox Use-After-Free), adapted from the original…

Docker-based CTF challenge exploiting CVE-2024-3552 in a web directory plugin. Start with docker-compose up and exploit the vulnerable WordPress-like…

An OWASP-aligned intentionally vulnerable platform for learning and testing AI, LLM, RAG, MCP, and Agentic AI security.

PoC for the recent critical vuln affecting OpenSSH versions < 9.3p2

Proof-of-concept demonstrating a Use-After-Free vulnerability in Firefox's RTCEncodedFrameBase via WebRTC Encoded Transforms, enabling heap…

Educational lab demonstrating a use-after-free (UAF) exploit in the Linux kernel's vsock subsystem for local privilege escalation to root, with…

Proof-of-concept exploit for CVE-2025-62215, a Windows kernel Use-After-Free vulnerability in SepTokenSidSharingEnabled. Includes a kernel driver and…

Xiaomi HyperOS AVCodec Medya Framework'ündeki Use-After-Free (CVE-2025-21082) Zafiyetinin Derinlemesine Analizi, Rust Simülasyonu ve İnteraktif Web…

Local privilege escalation proof-of-concept for CVE-2023-20938, a use-after-free in Android binder, achieving root and disabling SELinux on…

Exploit for CVE-2026-46215, a Linux kernel DRM GEM use-after-free local privilege escalation. Uses racing, slab spraying, and Dirty Pipe-style file…

A FREE comprehensive reverse engineering tutorial covering x86, x64, 32-bit/64-bit ARM, 8-bit AVR and 32-bit RISC-V architectures.

Some good resources for getting started with application security

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…