
shellshock-cve-lab
Intentionally vulnerable CGI lab for Shellshock (CVE-2014-6271) with a Python RFC-3875 server and GNU bash 4.2, designed for isolated security…

Intentionally vulnerable CGI lab for Shellshock (CVE-2014-6271) with a Python RFC-3875 server and GNU bash 4.2, designed for isolated security…

Intentionally vulnerable Log4j 2.14.1 HTTP service for hands-on practice with CVE-2021-44228 (Log4Shell) in an isolated sandbox environment.

Intentionally vulnerable Hospital Management System demonstrating SQL injection (CVE-2023-7172) with Docker setup and PoC for educational security…

Intentionally vulnerable app for hands-on CVE-2025-64459 practice, enabling guided exploitation and vulnerability analysis in security training.

Local intentionally vulnerable lab with a guided workshop and CTF challenges for practicing Git push-option RCE, unsafe deserialization,…

This is an intentionally vulnerable smart contract truffle deployment aimed at allowing those interested in smart contract security to exploit a wide…

A self-hosted vulnerable Next.js environment running on Docker for simulating CVE-2025-55182. Built for educational security research and CTF…

Intentionally vulnerable Next.js application demonstrating CVE-2025-55182 RCE via unsafe deserialization in React Server Components. Includes exploit…

Dockerized Spring Boot service intentionally vulnerable to Log4Shell (CVE-2021-44228) for testing detection tools, payloads, and exploit capabilities…

CVE-2021-3007 Vulnerable Test Environment - Laminas/Zend Framework Deserialization RCE

Intentionally vulnerable Next.js app for CVE-2025-55182 security research and CTF challenges

An intentionally vulnerable webapp to get your hands dirty with CVE-2022-42889.

Intentionally vulnerable Spring app to test CVE-2022-22965

Sample Spring Boot application intentionally vulnerable to Log4j2 CVE-2021-45105 for practicing exploitation and understanding infinite loop…

Intentionally vulnerable Next.js environment for testing security scanners against CVE-2025-55182, with PoC exploit and detection guidance.

A Java application intentionally vulnerable to CVE-2021-44228

Target Code + Exploit

Intentionally vulnerable Next.js environment with PoC exploit and detection templates for CVE-2025-55182 (React2Shell RCE), enabling security testing…