Vulnerable Environments

Browse our collection of pre-built vulnerable environments for security research and education. Each environment is containerized with Docker and comes with detailed documentation.

36 Results in Webserver

RCEDeserializationWebserver

Tomcat Session Deserialization Remote Code Execution

Explore the Tomcat Session Deserialization Remote Code Execution vulnerability and learn how to exploit it.

CVE-2025-24813
Created 16 days ago
Path TraversalWebserver

GlassFish 4.1.0 Arbitrary File Read

Explore the GlassFish 4.1.0 Arbitrary File Read vulnerability and learn how to exploit it.

CVE-2017-1000028
Created 24 days ago
RCEDeserializationWebserver

Adobe ColdFusion XML Deserialization Leads to RCE

Explore the Adobe ColdFusion XML Deserialization Leads to RCE vulnerability and learn how to exploit it.

CVE-2023-29300
Created a year ago
RCEPath TraversalWebserver

Adobe ColdFusion Local File Inclusion Leads to RCE

Explore the Adobe ColdFusion Local File Inclusion Leads to RCE vulnerability and learn how to exploit it.

CVE-2023-26360
Created a year ago
RCEWebserver

WebLogic Unauthorized Remote Code Execution

Explore the WebLogic Unauthorized Remote Code Execution vulnerability and learn how to exploit it.

CVE-2023-21839
Created 2 years ago
RCEAuth BypassWebserver

Apache APISIX Dashboard API Permission Bypass to RCE

Explore the Apache APISIX Dashboard API Permission Bypass to RCE vulnerability and learn how to exploit it.

CVE-2021-45232
Created 2 years ago
RCEHard CodingWebserver

Apache APISIX Hardcoded API Token Leads to RCE

Explore the Apache APISIX Hardcoded API Token Leads to RCE vulnerability and learn how to exploit it.

CVE-2020-13945
Created 3 years ago
SSRFWebserver

Apache HTTP Server 2.4.48 mod_proxy SSRF

Explore the Apache HTTP Server 2.4.48 mod_proxy SSRF vulnerability and learn how to exploit it.

CVE-2021-40438
Created 3 years ago
Path TraversalWebserver

Apache HTTP Server 2.4.50 Path Traversal

Explore the Apache HTTP Server 2.4.50 Path Traversal vulnerability and learn how to exploit it.

CVE-2021-42013
Created 3 years ago
Path TraversalWebserver

Apache HTTP Server 2.4.49 Path Traversal

Explore the Apache HTTP Server 2.4.49 Path Traversal vulnerability and learn how to exploit it.

CVE-2021-41773
Created 3 years ago
Info DisclosureWebserver

Jetty WEB-INF Sensitive Information Disclosure

Explore the Jetty WEB-INF Sensitive Information Disclosure vulnerability and learn how to exploit it.

CVE-2021-34429
Created 4 years ago
Info DisclosureWebserver

Jetty WEB-INF Sensitive Information Disclosure

Explore the Jetty WEB-INF Sensitive Information Disclosure vulnerability and learn how to exploit it.

CVE-2021-28164
Created 4 years ago
Info DisclosureWebserver

Jetty Common Servlets Component ConcatServlet Information Disclosure

Explore the Jetty Common Servlets Component ConcatServlet Information Disclosure vulnerability and learn how to exploit it.

CVE-2021-28169
Created 4 years ago
RCEWebserver

WebLogic Management Console Unauthorized Remote Command Execution

Explore the WebLogic Management Console Unauthorized Remote Command Execution vulnerability and learn how to exploit it.

CVE-2020-14882
Created 4 years ago
Auth BypassPath TraversalWebserver

Apache Tomcat AJP Bug

Explore the Apache Tomcat AJP Bug vulnerability and learn how to exploit it.

CVE-2020-1938
Created 5 years ago
Auth BypassWebserver

AppWeb Authentication Bypass

Explore the AppWeb Authentication Bypass vulnerability and learn how to exploit it.

CVE-2018-8715
Created 6 years ago
RCEWebserver

Apache HTTP Server SSI Remote Command Execution

Explore the Apache HTTP Server SSI Remote Command Execution vulnerability and learn how to exploit it.

N/A
Created 6 years ago
Path TraversalWebserver

ACME mini_httpd Arbitrary File Read

Explore the ACME mini_httpd Arbitrary File Read vulnerability and learn how to exploit it.

CVE-2018-18778
Created 6 years ago
File UploadWebserver

WebLogic Arbitrary File Upload

Explore the WebLogic Arbitrary File Upload vulnerability and learn how to exploit it.

CVE-2018-2894
Created 7 years ago
RCEDeserializationWebserver

JBoss 4.x JBossMQ JMS Deserialization Remote Code Execution

Explore the JBoss 4.x JBossMQ JMS Deserialization Remote Code Execution vulnerability and learn how to exploit it.

CVE-2017-7504
Created 7 years ago
Path TraversalWebserver

Adobe ColdFusion File Read

Explore the Adobe ColdFusion File Read vulnerability and learn how to exploit it.

CVE-2010-2861
Created 7 years ago
RCEDeserializationWebserver

Weblogic WLS Core Components Deserialization Remote Command Execution

Explore the Weblogic WLS Core Components Deserialization Remote Command Execution vulnerability and learn how to exploit it.

CVE-2018-2628
Created 7 years ago
Webserver

Apache HTTPD Newline Parsing Vulnerability

Explore the Apache HTTPD Newline Parsing Vulnerability vulnerability and learn how to exploit it.

CVE-2017-15715
Created 7 years ago
RCEDeserializationWebserver

JBoss JMXInvokerServlet Deserialization Remote Code Execution

Explore the JBoss JMXInvokerServlet Deserialization Remote Code Execution vulnerability and learn how to exploit it.

N/A
Created 7 years ago
Webserver

Apache HTTPD Multiple Extension Parsing Vulnerability

Explore the Apache HTTPD Multiple Extension Parsing Vulnerability vulnerability and learn how to exploit it.

N/A
Created 7 years ago
Webserver

Nginx Parsing Vulnerability

Explore the Nginx Parsing Vulnerability vulnerability and learn how to exploit it.

N/A
Created 7 years ago
DeserializationRCEWebserver

Adobe ColdFusion Deserialization

Explore the Adobe ColdFusion Deserialization vulnerability and learn how to exploit it.

CVE-2017-3066
Created 7 years ago
RCEDeserializationWebserver

WebLogic < 10.3.6 'wls-wsat' XMLDecoder Deserialization Remote Command Execution

Explore the WebLogic < 10.3.6 'wls-wsat' XMLDecoder Deserialization Remote Command Execution vulnerability and learn how to exploit it.

CVE-2017-10271
Created 7 years ago
RCEDeserializationWebserver

JBoss 5.x/6.x Deserialization Remote Code Execution

Explore the JBoss 5.x/6.x Deserialization Remote Code Execution vulnerability and learn how to exploit it.

CVE-2017-12149
Created 7 years ago
File UploadWebserver

Tomcat Arbitrary Writing of Files in the PUT Method

Explore the Tomcat Arbitrary Writing of Files in the PUT Method vulnerability and learn how to exploit it.

CVE-2017-12615
Created 8 years ago
Webserver

Nginx Filename Logic Vulnerability

Explore the Nginx Filename Logic Vulnerability vulnerability and learn how to exploit it.

CVE-2013-4547
Created 8 years ago
Info DisclosureWebserver

Nginx Cache Leak by Integer Overflow

Explore the Nginx Cache Leak by Integer Overflow vulnerability and learn how to exploit it.

CVE-2017-7529
Created 8 years ago
Webserver

Nginx Misconfiguration Vulnerabilities

Explore the Nginx Misconfiguration Vulnerabilities vulnerability and learn how to exploit it.

N/A
Created 8 years ago
SSRFWebserver

Weblogic UDDI Explorer Server-Side Request Forgery (SSRF)

Explore the Weblogic UDDI Explorer Server-Side Request Forgery (SSRF) vulnerability and learn how to exploit it.

N/A
Created 8 years ago
RCEPath TraversalWebserver

WebLogic Weak Password, Arbitrary File Read and Remote Code Execution

Explore the WebLogic Weak Password, Arbitrary File Read and Remote Code Execution vulnerability and learn how to exploit it.

N/A
Created 8 years ago
Auth BypassWebserver

Tomcat Weak Password

Explore the Tomcat Weak Password vulnerability and learn how to exploit it.

N/A
Created 8 years ago