
vuln-app-CVE-2025-55182
Intentionally vulnerable Next.js application demonstrating CVE-2025-55182 RCE via unsafe deserialization in React Server Components. Includes exploit…

Intentionally vulnerable Next.js application demonstrating CVE-2025-55182 RCE via unsafe deserialization in React Server Components. Includes exploit…

Local intentionally vulnerable lab with a guided workshop and CTF challenges for practicing Git push-option RCE, unsafe deserialization,…

Educational examples porting Linux kernel vulnerabilities to Rust, featuring intentionally vulnerable code and exploits for learning kernel security…

Dockerized Spring Boot service intentionally vulnerable to Log4Shell (CVE-2021-44228) for testing detection tools, payloads, and exploit capabilities…

Intentionally vulnerable app for hands-on CVE-2025-64459 practice, enabling guided exploitation and vulnerability analysis in security training.

Intentionally vulnerable Hospital Management System demonstrating SQL injection (CVE-2023-7172) with Docker setup and PoC for educational security…

Runs a fleet of intentionally vulnerable web/API apps in isolated Docker stacks for local penetration testing and validating scanner findings with…

Simple flask application to implement an intentionally vulnerable web app to demo CVE-2023-2822.

Intentionally vulnerable Spring app to test CVE-2022-22965

Intentionally vulnerable machine learning model for hands-on security training. Explore common ML vulnerabilities, adversarial attacks, and defensive…

Intentionally vulnerable Next.js environment with PoC exploit and detection templates for CVE-2025-55182 (React2Shell RCE), enabling security testing…

Intentionally vulnerable Next.js app for CVE-2025-55182 security research and CTF challenges

An intentionally vulnerable webapp to get your hands dirty with CVE-2022-42889.

Intentionally vulnerable Log4j 2.14.1 demo for Sysdig CNAPP scanning (CVE-2021-44228)

React2Shell (CVE-2025-55182) – An intentionally vulnerable Next.js application created for educational and research purposes.

Intentionally vulnerable VM-hosted Java shop — Log4Shell (CVE-2021-44228) workshop lab (EC2 / Azure VM / GCE)

Intentionally vulnerable Next.js environment for testing security scanners against CVE-2025-55182, with PoC exploit and detection guidance.

Intentionally vulnerable Next.js corporate landing page demonstrating CVE-2025-55182, a JSON injection leading to RCE/SSRF via unsafe deserialization…