Vulnerable Environments

Browse our collection of pre-built vulnerable environments for security research and education. Each environment is containerized with Docker and comes with detailed documentation.

40 Results in Framework

Auth BypassFramework

Next.js Middleware Authorization Bypass

Explore the Next.js Middleware Authorization Bypass vulnerability and learn how to exploit it.

CVE-2025-29927
Created 10 days ago
Path TraversalFramework

Struts2 S2-067 Upload Path Traversal

Explore the Struts2 S2-067 Upload Path Traversal vulnerability and learn how to exploit it.

CVE-2024-53677
Created 2 months ago
Path TraversalFramework

Struts2 S2-066 Upload Path Traversal

Explore the Struts2 S2-066 Upload Path Traversal vulnerability and learn how to exploit it.

CVE-2023-50164
Created 2 months ago
Auth BypassFramework

Spring Security Authorization Bypass in RegexRequestMatcher

Explore the Spring Security Authorization Bypass in RegexRequestMatcher vulnerability and learn how to exploit it.

CVE-2022-22978
Created 3 years ago
SQL InjectionFramework

Django Trunc(kind) and Extract(lookup_name) SQL Injection

Explore the Django Trunc(kind) and Extract(lookup_name) SQL Injection vulnerability and learn how to exploit it.

CVE-2022-34265
Created 3 years ago
RCEFramework

Spring Framework Data Binding Remote Code Execution on JDK 9+

Explore the Spring Framework Data Binding Remote Code Execution on JDK 9+ vulnerability and learn how to exploit it.

CVE-2022-22965
Created 3 years ago
RCEExpression InjectionFramework

Spring Cloud Function SpEL Expression Command Injection

Explore the Spring Cloud Function SpEL Expression Command Injection vulnerability and learn how to exploit it.

CVE-2022-22963
Created 3 years ago
RCEExpression InjectionFramework

Spring Cloud Gateway Actuator API SpEL Expression Injection Command Execution

Explore the Spring Cloud Gateway Actuator API SpEL Expression Injection Command Execution vulnerability and learn how to exploit it.

CVE-2022-22947
Created 3 years ago
SQL InjectionFramework

Django QuerySet.order_by() SQL Injection

Explore the Django QuerySet.order_by() SQL Injection vulnerability and learn how to exploit it.

CVE-2021-35042
Created 4 years ago
RCEFramework

Laravel Ignition 2.5.1 Remote Code Execution

Explore the Laravel Ignition 2.5.1 Remote Code Execution vulnerability and learn how to exploit it.

CVE-2021-3129
Created 4 years ago
RCEFramework

Struts2 S2-061 Remote Command Execution

Explore the Struts2 S2-061 Remote Command Execution vulnerability and learn how to exploit it.

CVE-2020-17530
Created 4 years ago
RCEFramework

Struts2 S2-059 Remote Command Execution

Explore the Struts2 S2-059 Remote Command Execution vulnerability and learn how to exploit it.

CVE-2019-0230
Created 5 years ago
RCEFramework

S2-032 Remote Code Execution

Explore the S2-032 Remote Code Execution vulnerability and learn how to exploit it.

CVE-2016-3081
Created 5 years ago
SQL InjectionFramework

Django GIS functions and aggregates on Oracle SQL Injection

Explore the Django GIS functions and aggregates on Oracle SQL Injection vulnerability and learn how to exploit it.

CVE-2020-9402
Created 5 years ago
RCEFramework

S2-045 Remote Code Execution

Explore the S2-045 Remote Code Execution vulnerability and learn how to exploit it.

CVE-2017-5638
Created 5 years ago
RCEFramework

S2-046 Remote Code Execution

Explore the S2-046 Remote Code Execution vulnerability and learn how to exploit it.

CVE-2017-5638
Created 5 years ago
SQL InjectionFramework

Django JSONField/HStoreField SQL Injection

Explore the Django JSONField/HStoreField SQL Injection vulnerability and learn how to exploit it.

CVE-2019-14234
Created 6 years ago
Path TraversalFramework

Ruby on Rails Path Traversal and Arbitrary File Read

Explore the Ruby on Rails Path Traversal and Arbitrary File Read vulnerability and learn how to exploit it.

CVE-2019-5418
Created 6 years ago
Path TraversalFramework

Ruby on Rails Path Traversal

Explore the Ruby on Rails Path Traversal vulnerability and learn how to exploit it.

CVE-2018-3760
Created 7 years ago
RCEFramework

Struts2 S2-057 Remote Command Execution

Explore the Struts2 S2-057 Remote Command Execution vulnerability and learn how to exploit it.

CVE-2018-11776
Created 7 years ago
Framework

Django < 2.0.8 Open Redirect in CommonMiddleware

Explore the Django < 2.0.8 Open Redirect in CommonMiddleware vulnerability and learn how to exploit it.

CVE-2018-14574
Created 7 years ago
RCEFramework

Spring Messaging Remote Command Execution

Explore the Spring Messaging Remote Command Execution vulnerability and learn how to exploit it.

CVE-2018-1270
Created 7 years ago
RCEFramework

Spring Data Commons Remote Command Execution

Explore the Spring Data Commons Remote Command Execution vulnerability and learn how to exploit it.

CVE-2018-1273
Created 7 years ago
RCEFramework

Spring WebFlow Remote Code Execution

Explore the Spring WebFlow Remote Code Execution vulnerability and learn how to exploit it.

CVE-2017-4971
Created 7 years ago
RCEFramework

Spring Data Rest Remote Command Execution

Explore the Spring Data Rest Remote Command Execution vulnerability and learn how to exploit it.

CVE-2017-8046
Created 7 years ago
RCEFramework

Spring Security Oauth2 Remote Command Execution

Explore the Spring Security Oauth2 Remote Command Execution vulnerability and learn how to exploit it.

CVE-2016-4977
Created 7 years ago
RCEFramework

S2-016 Remote Code Execution

Explore the S2-016 Remote Code Execution vulnerability and learn how to exploit it.

CVE-2013-2251
Created 7 years ago
RCEFramework

S2-053 Remote Code Execution

Explore the S2-053 Remote Code Execution vulnerability and learn how to exploit it.

CVE-2017-12611
Created 8 years ago
RCEFramework

S2-052 Remote Code Execution

Explore the S2-052 Remote Code Execution vulnerability and learn how to exploit it.

CVE-2017-9805
Created 8 years ago
XSSFramework

Django 500 Debug Page Cross-Site Scripting (XSS)

Explore the Django 500 Debug Page Cross-Site Scripting (XSS) vulnerability and learn how to exploit it.

CVE-2017-12794
Created 8 years ago
RCEFramework

S2-048 Remote Code Execution

Explore the S2-048 Remote Code Execution vulnerability and learn how to exploit it.

CVE-2017-9791
Created 8 years ago
RCEFramework

S2-015 Remote Code Execution

Explore the S2-015 Remote Code Execution vulnerability and learn how to exploit it.

CVE-2013-2134CVE-2013-2135
Created 8 years ago
SSTIRCEFramework

Flask (Jinja2) Server-Side Template Injection

Explore the Flask (Jinja2) Server-Side Template Injection vulnerability and learn how to exploit it.

N/A
Created 8 years ago
RCEFramework

S2-013 Remote Code Execution

Explore the S2-013 Remote Code Execution vulnerability and learn how to exploit it.

CVE-2013-1966
Created 8 years ago
RCEFramework

S2-012 Remote Code Execution

Explore the S2-012 Remote Code Execution vulnerability and learn how to exploit it.

CVE-2013-1965
Created 8 years ago
RCEFramework

S2-009 Remote Code Execution

Explore the S2-009 Remote Code Execution vulnerability and learn how to exploit it.

CVE-2011-3923
Created 8 years ago
RCEFramework

S2-008 Remote Code Execution

Explore the S2-008 Remote Code Execution vulnerability and learn how to exploit it.

CVE-2012-0391
Created 8 years ago
RCEFramework

S2-007 Remote Code Execution

Explore the S2-007 Remote Code Execution vulnerability and learn how to exploit it.

N/A
Created 8 years ago
RCEFramework

S2-005 Remote Code Execution

Explore the S2-005 Remote Code Execution vulnerability and learn how to exploit it.

CVE-2010-1870
Created 8 years ago
RCEFramework

S2-001 Remote Code Execution

Explore the S2-001 Remote Code Execution vulnerability and learn how to exploit it.

N/A
Created 8 years ago