Vulnerable Environments

Browse our collection of pre-built vulnerable environments for security research and education. Each environment is containerized with Docker and comes with detailed documentation.

35 Results in Deserialization

RCEDeserialization

Apache Superset Python Pickle Deserialization Leads to RCE

Explore the Apache Superset Python Pickle Deserialization Leads to RCE vulnerability and learn how to exploit it.

CVE-2023-37941
Created 5 days ago
RCEDeserializationWebserver

Tomcat Session Deserialization Remote Code Execution

Explore the Tomcat Session Deserialization Remote Code Execution vulnerability and learn how to exploit it.

CVE-2025-24813
Created 16 days ago
RCEDeserialization

Apache HertzBeat SnakeYaml Deserialization Remote Code Execution

Explore the Apache HertzBeat SnakeYaml Deserialization Remote Code Execution vulnerability and learn how to exploit it.

CVE-2024-42323
Created 24 days ago
RCEDeserializationWebserver

Adobe ColdFusion XML Deserialization Leads to RCE

Explore the Adobe ColdFusion XML Deserialization Leads to RCE vulnerability and learn how to exploit it.

CVE-2023-29300
Created a year ago
DeserializationRCE

Unsafe deserialization of XMLRPC arguments in Apache OFBiz

Explore the Unsafe deserialization of XMLRPC arguments in Apache OFBiz vulnerability and learn how to exploit it.

CVE-2023-49070
Created a year ago
RCEDeserializationMessage Queue

Apache ActiveMQ OpenWire Protocol Deserialization RCE

Explore the Apache ActiveMQ OpenWire Protocol Deserialization RCE vulnerability and learn how to exploit it.

CVE-2023-46604
Created a year ago
DeserializationRCE

Neo4j Shell Server Deserialization

Explore the Neo4j Shell Server Deserialization vulnerability and learn how to exploit it.

CVE-2021-34371
Created 4 years ago
DeserializationRCE

Apache Dubbo Java Deserialization

Explore the Apache Dubbo Java Deserialization vulnerability and learn how to exploit it.

CVE-2019-17564
Created 4 years ago
DeserializationAuth Bypass

Celery <4.0 Redis Unauthorized Access and Pickle Deserialization

Explore the Celery <4.0 Redis Unauthorized Access and Pickle Deserialization vulnerability and learn how to exploit it.

N/A
Created 4 years ago
RCEDeserialization

XStream Deserialization Command Execution

Explore the XStream Deserialization Command Execution vulnerability and learn how to exploit it.

CVE-2021-21351
Created 4 years ago
RCEDeserialization

XStream Deserialization Command Execution

Explore the XStream Deserialization Command Execution vulnerability and learn how to exploit it.

CVE-2021-29505
Created 4 years ago
RCEDeserialization

Apache OfBiz Deserialization Command Execution

Explore the Apache OfBiz Deserialization Command Execution vulnerability and learn how to exploit it.

CVE-2020-9496
Created 4 years ago
DeserializationRCE

Mojarra JSF ViewState Deserialization

Explore the Mojarra JSF ViewState Deserialization vulnerability and learn how to exploit it.

N/A
Created 5 years ago
RCEDeserialization

Apereo CAS 4.1 Deserialization Command Execution

Explore the Apereo CAS 4.1 Deserialization Command Execution vulnerability and learn how to exploit it.

N/A
Created 5 years ago
RCEDeserialization

Liferay Portal CE Deserialization Remote Code Execution

Explore the Liferay Portal CE Deserialization Remote Code Execution vulnerability and learn how to exploit it.

CVE-2020-7961
Created 5 years ago
RCEDeserialization

Java < JDK8u232_b09 RMI Registry Deserialization Remote Code Execution Bypass

Explore the Java < JDK8u232_b09 RMI Registry Deserialization Remote Code Execution Bypass vulnerability and learn how to exploit it.

N/A
Created 5 years ago
RCEDeserialization

Java <= JDK 8u111 RMI Registry Deserialization Remote Code Execution

Explore the Java <= JDK 8u111 RMI Registry Deserialization Remote Code Execution vulnerability and learn how to exploit it.

N/A
Created 5 years ago
RCEDeserializationHard Coding

Apache Shiro 1.2.4 Deserialization Remote Code Execution

Explore the Apache Shiro 1.2.4 Deserialization Remote Code Execution vulnerability and learn how to exploit it.

CVE-2016-4437
Created 5 years ago
RCEDeserialization

Fastjson 1.2.24 Deserialization Remote Command Execution

Explore the Fastjson 1.2.24 Deserialization Remote Command Execution vulnerability and learn how to exploit it.

CVE-2017-18349
Created 6 years ago
RCEDeserialization

Fastjson 1.2.47 Deserialization Remote Command Execution

Explore the Fastjson 1.2.47 Deserialization Remote Command Execution vulnerability and learn how to exploit it.

N/A
Created 6 years ago
RCEDeserializationCMS

Drupal Core 8 PECL YAML Deserialization Remote Code Execution

Explore the Drupal Core 8 PECL YAML Deserialization Remote Code Execution vulnerability and learn how to exploit it.

CVE-2017-6920
Created 6 years ago
RCEDeserializationCMS

Drupal Remote Code Execution by phar deserialization

Explore the Drupal Remote Code Execution by phar deserialization vulnerability and learn how to exploit it.

CVE-2019-6339
Created 6 years ago
RCEDeserialization

Jackson-databind Deserialization Remote Command Execution

Explore the Jackson-databind Deserialization Remote Command Execution vulnerability and learn how to exploit it.

CVE-2017-7525
Created 6 years ago
DeserializationRCE

phpmyadmin scripts/setup.php Deserialization

Explore the phpmyadmin scripts/setup.php Deserialization vulnerability and learn how to exploit it.

N/A
Created 7 years ago
RCEDeserializationWebserver

JBoss 4.x JBossMQ JMS Deserialization Remote Code Execution

Explore the JBoss 4.x JBossMQ JMS Deserialization Remote Code Execution vulnerability and learn how to exploit it.

CVE-2017-7504
Created 7 years ago
RCEDeserializationWebserver

Weblogic WLS Core Components Deserialization Remote Command Execution

Explore the Weblogic WLS Core Components Deserialization Remote Command Execution vulnerability and learn how to exploit it.

CVE-2018-2628
Created 7 years ago
RCEDeserializationWebserver

JBoss JMXInvokerServlet Deserialization Remote Code Execution

Explore the JBoss JMXInvokerServlet Deserialization Remote Code Execution vulnerability and learn how to exploit it.

N/A
Created 7 years ago
RCEDeserialization

Apache Log4j TCP Server Deserialization Remote Code Execution

Explore the Apache Log4j TCP Server Deserialization Remote Code Execution vulnerability and learn how to exploit it.

CVE-2017-5645
Created 7 years ago
DeserializationRCEWebserver

Adobe ColdFusion Deserialization

Explore the Adobe ColdFusion Deserialization vulnerability and learn how to exploit it.

CVE-2017-3066
Created 7 years ago
RCEDeserialization

Apache JMeter RMI Deserialization Remote Code Execution

Explore the Apache JMeter RMI Deserialization Remote Code Execution vulnerability and learn how to exploit it.

CVE-2018-1297
Created 7 years ago
DeserializationRCEMessage Queue

Apache ActiveMQ Deserialization

Explore the Apache ActiveMQ Deserialization vulnerability and learn how to exploit it.

CVE-2015-5254
Created 7 years ago
RCEDeserializationWebserver

WebLogic < 10.3.6 'wls-wsat' XMLDecoder Deserialization Remote Command Execution

Explore the WebLogic < 10.3.6 'wls-wsat' XMLDecoder Deserialization Remote Command Execution vulnerability and learn how to exploit it.

CVE-2017-10271
Created 7 years ago
DeserializationRCECMS

Joomla 3.4.5 Deserialization

Explore the Joomla 3.4.5 Deserialization vulnerability and learn how to exploit it.

CVE-2015-8562
Created 7 years ago
RCEDeserializationWebserver

JBoss 5.x/6.x Deserialization Remote Code Execution

Explore the JBoss 5.x/6.x Deserialization Remote Code Execution vulnerability and learn how to exploit it.

CVE-2017-12149
Created 7 years ago
RCEDeserialization

Python Unpickle Deserialization Remote Code Execution

Explore the Python Unpickle Deserialization Remote Code Execution vulnerability and learn how to exploit it.

N/A
Created 8 years ago