
CVE_Demo
Curated collection of CVE demonstrations with fix recommendations for hands-on vulnerability analysis and educational exploitation practice.

Curated collection of CVE demonstrations with fix recommendations for hands-on vulnerability analysis and educational exploitation practice.

Proof of concept with GDB‑assisted exploitation (educational / lab use only)

Spring4Shell (CVE-2022-22965) proof-of-concept with Docker lab, detailed vulnerability analysis, and debugging setup for educational exploitation…

Safe, controlled mock system simulating CVE-2021-4034 (PwnKit) with out-of-bounds read/write, environment variable injection, and kernel defense…

Minimal test repository demonstrating Git's CVE-2017-1000117 recursive clone vulnerability for educational exploitation verification.

Python script with GUI for automated payload testing against login endpoints, designed for educational exploitation simulation and vulnerability…

Linux kernel source tree with a targeted patch for CVE-2020-14381, demonstrating a specific kernel vulnerability and its fix for educational…

Interactive demo of CVE-2022-45059 Varnish Cache request smuggling vulnerability. Includes Spring Boot web app, vulnerable proxy, automated victim…

Minimal Rust project demonstrating CVE-2021-42574 with compile-time behavior differences between patched and vulnerable rustc versions for…

Dockerized vulnerable web application demonstrating the Log4j CVE-2021-44228 remote code execution vulnerability for educational exploitation and…

Docker container with a pre-configured vulnerable environment for CVE-2019-9184, designed for security testing and educational exploitation practice.

Docker container providing a vulnerable environment for CVE-2018-3810, designed for security testing and educational exploitation practice within…

Proof-of-concept exploit for CVE-2026-31431, a Linux local privilege escalation vulnerability, demonstrating kernel exploitation for educational and…

Proof-of-concept exploit for CVE-2017-1000117, a remote code execution vulnerability in git clients prior to v2.14.1, demonstrating recursive clone…

Sample Spring Boot web application vulnerable to Log4j2 CVE-2021-45046, demonstrating JNDI injection and infinite loop exploitation for educational…

Docker-based vulnerable environment and Python exploit script demonstrating CVE-2017-5638 (Apache Struts2 RCE) for educational security testing.

CVE-2014-0050 Vulnerable site sample

Research and analysis of CVE-2025-55315, providing a Python script for studying the vulnerability's technical details and potential exploitation…