
Awesome-CloudSec-Labs
Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.

Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.

CVE-2026-60004 — Gitea <= 1.27.0 Pre-Auth RCE

Local intentionally vulnerable lab with a guided workshop and CTF challenges for practicing Git push-option RCE, unsafe deserialization,…

Real world and CTFs exploiting web/binary POCs.

🛡️ CVE Proof-of-Concept Hub — 4 PUBLISHED CVEs · 5 under review (VulnCheck) · SuiteCRM batch withdrawn


Reproduction of cve-2025-53779-kerberos_bypass_reproduction

OS command injection vulnerability in Samba that received the maximum possible CVSS v3.1 score of 10.0

An isolated Vagrant testbed designed to simulate a complete attack chain: Initial access via the Nginx heap buffer overflow (CVE-2026-42533) followed…

VULCONHUB provides access to files to build your own hands-on vulnerable container image to learn and practice security

Analysis and end-to-end implementation of the patched wordpress RCE vulnerability - CVE-2026-60137 and CVE-2026-63030


Lab introduction to ZeroLogon


Learn about the vulnerability known as PrintNightmare (CVE-2021-1675) and (CVE-2021-34527)

Atlassian, CVE-2022-26134 An interactive lab showcasing the Confluence Server and Data Center un-authenticated RCE vulnerability.