CVE Labs & Environments

The largest open collection of weaponized CVE lab environments on the internet. Spin up a vulnerable target, pop a shell, verify the patch - in seconds. Every EIP lab ships with working proof-of-concept exploit code, vulnerable and patched multi-arch Docker images, and full AI-driven analysis covering root cause, attack surface, and verified remediation. Community labs extend coverage with thousands of additional environments discovered from open-source exploit repositories across GitHub.

GitHub · API

645 Total Labs
72 EIP Labs
573 Community
98 EIP Images
1371 Community Images
50 Critical
17 High
5 Medium
EIP Labs
72
CVEForge-authored · Full analysis · Multi-arch Docker images
CVE-2026-45829 ChromaDB >=1.0.0 - Unauthenticated Remote Code Execution via Malicious Model Repository
CRITICALRCERELIABLEWORKING POC

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in...

CMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-45829-vulnerable:latest
Docker Lab
CVE-2026-42859 Neat VNC: Buffer overflow due to oversized RSA public keys
HIGHRCERELIABLEWORKING POC

Neat VNC is a VNC server library. Prior to 0.9.6, a pre-authentication stack buffer overflow exists in neatvnc in the RSA-AES security type handler. An unauthenticated remote attacker who can reach the VNC listening socket can send a crafted security type 5 (RSA-AES) or security type 129...

CMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-42859-vulnerable:latest
Docker Lab
CVE-2026-3296 Everest Forms <= 3.4.3 - Unauthenticated PHP Object Injection via Form Entry Metadata
CRITICALRCERELIABLEWORKING POC
9.8

The Everest Forms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.4.3 via deserialization of untrusted input from form entry metadata. This is due to the html-admin-page-entries-view.php file calling PHP's native unserialize() on stored entry...

CMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-3296-vulnerable:latest
Docker Lab
CVE-2026-34980 OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network
HIGHRCERELIABLEWORKING POC
7.5

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-exposed cupsd with a shared target queue, an unauthorized client can send a Print-Job to that shared PostScript queue without authentication. The server...

CMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-34980-vulnerable:latest
Docker Lab
CVE-2026-35414 OpenSSH < 10.3 - Always-Incorrect Control Flow Implementation in Authorized Keys Principals Handling
MEDIUMAUTH BYPASSRELIABLEWORKING POC
4.2

OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.

CMODERATE
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2026-35414-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2026-35414-vulnerable:latest
Docker Lab
CVE-2026-33765 Pi-hole Web <6.0 savesettings.php - Command Injection
CRITICALRCERELIABLEWORKING POC
9.8

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking application. Versions prior to 6.0 have a critical OS Command Injection vulnerability in the savesettings.php file. The application takes the user-controlled $_POST['webtheme']...

CTRIVIAL
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2026-33765-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2026-33765-vulnerable:latest
CVE-2026-33765 lab
CVE-2026-4105 Red Hat Enterprise Linux 10 - Improper Access Control via systemd-machined RegisterMachine D-Bus Method
MEDIUMLPERELIABLEWORKING POC
6.7

A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with...

CMODERATE
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2026-4105-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2026-4105-vulnerable:latest
CVE-2026-4105 lab
CVE-2026-30860 WeKnora <0.2.12 - RCE via SQL Injection
CRITICALRCERELIABLEWORKING POC
9.9

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a remote code execution (RCE) vulnerability exists in the application's database query functionality. The validation system fails to recursively inspect child nodes...

CMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-30860-vulnerable:latest
CVE-2026-30860 lab
CVE-2026-30861 WeKnora 0.2.5-0.2.9 - Unauthenticated Remote Code Execution via MCP stdio Configuration Validation Bypass
CRITICALRCERELIABLEWORKING POC
9.9

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. From version 0.2.5 to before version 0.2.10, an unauthenticated remote code execution (RCE) vulnerability exists in the MCP stdio configuration validation. The application allows unrestricted...

CMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-30861-vulnerable:latest
CVE-2026-30861 lab
CVE-2026-28391 OpenClaw <2026.2.2 - Command Injection
CRITICALRCERELIABLEWORKING POC
9.8

OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec requests (non-default configuration), allowing attackers to bypass command approval restrictions. Remote attackers can craft command strings with shell metacharacters like & or...

CMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-28391-vulnerable:latest
CVE-2026-28391 lab
CVE-2025-59060 Apache Ranger <=2.7.0 - Auth Bypass
MEDIUMAUTH BYPASSRELIABLEWORKING POC
5.3

Hostname verification bypass issue in Apache Ranger NiFiRegistryClient/NiFiClient is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue.

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-59060-vulnerable:latest
CVE-2025-59060 lab
CVE-2026-2749 Centreon Open Tickets <25.10.3 - Path Traversal
CRITICALRCERELIABLEWORKING POC
9.9

Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10.3, 24.10.8, 24.04.7.

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-2749-vulnerable:latest
CVE-2026-2749 lab
CVE-2026-28268 Vikunja < 2.1.0 - Persistent Account Takeover via Password Reset Token Reuse
CRITICALAUTH BYPASSRELIABLEWORKING POC
9.8

Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerability exists in the password reset mechanism of vikunja/api that allows password reset tokens to be reused indefinitely. Due to a failure to invalidate tokens upon use and a...

PythonTRIVIAL
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-28268-vulnerable:latest
CVE-2026-28268 lab
CVE-2026-28370 OpenStack Vitrage <12.0.1,13.0.0,14.0.0,15.0.0 - Code Injection
CRITICALRCERELIABLEWORKING POC
9.1

In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger code execution on the Vitrage service host as the user the Vitrage service runs under. This may result in unauthorized access to the host and further...

PythonMODERATE
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2026-28370-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2026-28370-vulnerable:latest
CVE-2026-28370 lab
CVE-2026-28372 GNU inetutils <=2.7 - Privilege Escalation
HIGHLPERELIABLEWORKING POC
7.4

telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALS_DIRECTORY environment variable, and...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-28372-vulnerable:latest
CVE-2026-28372 lab
CVE-2026-28409 WeGIA < 3.6.5 - Authenticated Remote Code Execution via Database Restore Filename
CRITICALOTHERTHEORETICALSTUB
10.0

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA application's database restoration functionality. An attacker with administrative access (which can be obtained via the previously reported...

PythonTHEORETICAL
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2026-28409-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2026-28409-vulnerable:latest
CVE-2026-28409 lab
CVE-2026-28417 Vim < 9.2.0073 - OS Command Injection via netrw Plugin SCP URL Handler
MEDIUMRCERELIABLEWORKING POC
4.4

Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol handler), an attacker can execute arbitrary shell...

PythonTRIVIAL
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-28417-vulnerable:latest
CVE-2026-28417 lab
CVE-2026-28215 hoppscotch < 2026.2.0 - Unauthenticated Infrastructure Configuration Overwrite via Onboarding Endpoint
CRITICALAUTH BYPASSRELIABLEWORKING POC
9.1

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructure configuration of a self-hosted Hoppscotch instance including OAuth provider credentials and SMTP settings by sending a single HTTP POST request...

PythonTRIVIAL
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-28215-vulnerable:latest
CVE-2026-28215 lab
CVE-2025-69985 FUXA < 1.2.8 - Unauthenticated Authentication Bypass and Remote Code Execution via Referer Header Spoofing
CRITICALRCERELIABLEWORKING POC
9.8

FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts the HTTP "Referer" header to validate internal requests. A remote unauthenticated attacker can...

PythonTRIVIAL
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2025-69985-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-69985-vulnerable:latest
CVE-2025-69985 lab
CVE-2026-2635 MLflow - Unauthenticated Authentication Bypass via Default Credentials in basic_auth.ini
CRITICALAUTH BYPASSRELIABLEWORKING POC
9.8

MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the basic_auth.ini file. The...

PythonTRIVIAL
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2026-2635-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2026-2635-vulnerable:latest
CVE-2026-2635 lab
CVE-2026-26988 LibreNMS < 26.2.0 - SQL Injection via IPv6 Address Search in ajax_table.php
CRITICALSQLIRELIABLEWORKING POC
9.1

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Versions 25.12.0 and below contain an SQL Injection vulnerability in the ajax_table.php endpoint. The application fails to properly sanitize or parameterize user input when processing IPv6 address searches....

PythonMODERATE
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2026-26988-patched:latest
CVE-2026-26988 lab
CVE-2026-26321 OpenClaw <2026.2.14 - Path Traversal
HIGHINFO LEAK | SSRFRELIABLEWORKING POC
7.5

OpenClaw is a personal AI assistant. Prior to OpenClaw version 2026.2.14, the Feishu extension previously allowed `sendMediaFeishu` to treat attacker-controlled `mediaUrl` values as local filesystem paths and read them directly. If an attacker can influence tool calls (directly or via prompt...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-26321-vulnerable:latest
CVE-2026-26321 lab
CVE-2026-1868 GitLab AI Gateway <18.6.1-18.8.0 - DoS/Code Execution
CRITICALOTHERTHEORETICALSTUB
9.9

GitLab has remediated a vulnerability in the Duo Workflow Service component of GitLab AI Gateway affecting all versions of the AI Gateway from 18.1.6, 18.2.6, 18.3.1 to 18.6.1, 18.7.0, and 18.8.0 in which AI Gateway was vulnerable to insecure template expansion of user supplied data via crafted...

PythonTHEORETICAL
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-1868-vulnerable:latest
CVE-2026-1868 lab
CVE-2025-15467 OpenSSL 3.0.0-3.0.18, 3.3.0-3.3.5, 3.4.0-3.4.3, 3.5.0-3.5.4, 3.6.0 - Stack-based Buffer Overflow via CMS AEAD IV Parsing
HIGHRCERELIABLEWORKING POC
8.8

Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS...

PythonCOMPLEX
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-15467-vulnerable:latest
Docker Lab
CVE-2016-15057 Apache Continuum - Command Injection
CRITICALRCERELIABLEWORKING POC
9.9

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Continuum. This issue affects Apache Continuum: all versions. Attackers with access to the installations REST API can use this to invoke arbitrary...

PythonTRIVIAL
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2016-15057-vulnerable:latest
CVE-2016-15057 lab
CVE-2026-0760 Foundation Agents MetaGPT - Deserialization
CRITICALRCERELIABLEWORKING POC
9.8

Foundation Agents MetaGPT deserialize_message Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foundation Agents MetaGPT. Authentication is not required to exploit this...

PythonTRIVIAL
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-0760-vulnerable:latest
CVE-2026-0760 lab
CVE-2026-0761 Foundation Agents MetaGPT - Code Injection
CRITICALRCERELIABLEWORKING POC
9.8

Foundation Agents MetaGPT actionoutput_str_to_mapping Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foundation Agents MetaGPT. Authentication is not required to exploit this...

PythonMODERATE
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2026-0761-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2026-0761-vulnerable:latest
CVE-2026-0761 lab
CVE-2026-0765 Open WebUI - Authenticated Remote Code Execution via install_frontmatter_requirements Function
HIGHRCERELIABLEWORKING POC
8.8

Open WebUI PIP install_frontmatter_requirements Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Open WebUI. Authentication is required to exploit this vulnerability. The specific flaw exists...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-0765-vulnerable:latest
CVE-2026-0765 lab
CVE-2026-0766 Open WebUI - Authenticated Remote Code Execution via load_tool_module_by_id Function
HIGHRCERELIABLEWORKING POC
8.8

Open WebUI load_tool_module_by_id Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Open WebUI. Authentication is required to exploit this vulnerability. The specific flaw exists within the...

PythonTRIVIAL
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-0766-vulnerable:latest
CVE-2026-0766 lab
CVE-2026-0768 Langflow - Unauthenticated Remote Code Execution via Validate Endpoint Code Parameter
CRITICALRCERELIABLEWORKING POC
9.8

Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the code...

PythonTRIVIAL
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-0768-vulnerable:latest
CVE-2026-0768 lab
CVE-2026-0769 Langflow - Unauthenticated Remote Code Execution via eval_custom_component_code
CRITICALRCERELIABLEWORKING POC
9.8

Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the...

PythonTRIVIAL
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-0769-vulnerable:latest
CVE-2026-0769 lab
CVE-2026-0773 Upsonic - Unauthenticated Remote Code Execution via Cloudpickle Deserialization in add_tool Endpoint
CRITICALRCERELIABLEWORKING POC
9.8

Upsonic Cloudpickle Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Upsonic. Authentication is not required to exploit this vulnerability. The specific flaw exists within the...

PythonTRIVIAL
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-0773-vulnerable:latest
CVE-2026-0773 lab
CVE-2025-66524 Apache NiFi <2.6.0 - Deserialization
HIGHDESERIALIZATIONRELIABLEWORKING POC
8.8

Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Distribute Map Cache Client Service for storing and retrieving state information. The GetAsanaObject Processor used generic Java Object serialization and deserialization without...

PythonMODERATE
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2025-66524-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-66524-vulnerable:latest
Docker Lab
CVE-2025-67895 Apache Airflow Providers Edge3 < 2.0.0 - Remote Code Execution via Edge3 Worker RPC
CRITICALRCERELIABLEWORKING POC
9.8

Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on Airflow 2. The Edge3 provider support in Airflow 2 has been always development-only and not officially released, however if you installed and...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-67895-vulnerable:latest
CVE-2025-67895 lab
CVE-2025-26866 Apache HugeGraph < 1.7.0 - Remote Code Execution via Hessian Deserialization
HIGHRCERELIABLEWORKING POC
8.8

A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces IP-based authentication to restrict cluster membership and implements a strict class whitelist to harden the Hessian serialization process...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-26866-vulnerable:latest
CVE-2025-26866 lab
CVE-2025-66489 Cal.com < 5.9.8 - Authentication Bypass via TOTP Code
CRITICALAUTH BYPASSRELIABLEWORKING POC
9.8

Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker to bypass password verification when a TOTP code is provided, potentially gaining unauthorized access to user accounts. This issue exists due to problematic conditional logic...

PythonTRIVIAL
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-66489-vulnerable:latest
CVE-2025-66489 lab
CVE-2025-12421 Mattermost <11.0.2, 10.12.1, 10.11.4, 10.5.12 - Auth Bypass
CRITICALAUTH BYPASSRELIABLEWORKING POC
9.9

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-12421-vulnerable:latest
CVE-2025-12421 lab
CVE-2025-59390 Apache Druid <= 34.0.0 - Weak Cookie Signature Secret via ThreadLocalRandom
CRITICALAUTH BYPASSRELIABLEWORKING POC
9.8

Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is not explicitly set. In this case, the secret is generated using `ThreadLocalRandom`, which is not a crypto-graphically secure random number...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-59390-vulnerable:latest
CVE-2025-59390 lab
CVE-2025-10622 Red Hat Satellite - Command Injection
HIGHRCERELIABLEWORKING POC
8.0

A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_settings permissions to achieve arbitrary command execution on the underlying operating system via insufficient server-side validation of command whitelisting.

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-10622-vulnerable:latest
CVE-2025-10622 lab
CVE-2025-62507 Redis 8.2.0-8.2.2 - Stack-based Buffer Overflow via XACKDEL Command
HIGHRCERELIABLEWORKING POC
8.8

Redis is an open source, in-memory database that persists on disk. In versions 8.2.0 and above, a user can run the XACKDEL command with multiple ID's and trigger a stack buffer overflow, which may potentially lead to remote code execution. This issue is fixed in version 8.2.3. To workaround this...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-62507-vulnerable:latest
Docker Lab
CVE-2025-60355 zhangyd-c OneBlog <2.3.9 - Server-Side Template Injection
CRITICALRCERELIABLEWORKING POC
9.8

zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.

PythonMODERATE
Docker Images
admin docker pull ghcr.io/exploitintel/cve-2025-60355-admin:latest
builder docker pull ghcr.io/exploitintel/cve-2025-60355-builder:latest
mysql docker pull ghcr.io/exploitintel/cve-2025-60355-mysql:latest
web docker pull ghcr.io/exploitintel/cve-2025-60355-web:latest
CVE-2025-60355 lab
CVE-2025-62515 pyquokka <= 0.3.1 - Remote Code Execution via Unsafe Pickle Deserialization in FlightServer
CRITICALRCERELIABLEWORKING POC
9.8

pyquokka is a framework for making data lakes work for time series. In versions 0.3.1 and prior, the FlightServer class directly uses pickle.loads() to deserialize action bodies received from Flight clients without any sanitization or validation in the do_action() method. The vulnerable code is...

PythonTRIVIAL
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2025-62515-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-62515-vulnerable:latest
Docker Lab
CVE-2024-56143 Strapi 5.0.0-5.5.1 - Unauthenticated Private Field Exposure via Lookup Operator
HIGHINFO LEAKRELIABLEWORKING POC
8.2

Strapi is an open-source headless content management system. In versions from 5.0.0 to before 5.5.2, the lookup operator provided by the document service does not properly sanitize query parameters for private fields. An attacker can access private fields, including admin passwords and reset...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2024-56143-vulnerable:latest
CVE-2024-56143 lab
CVE-2025-11539 Grafana Image Renderer 1.0.0-4.0.16 - Remote Code Execution via CSV Endpoint File Path Parameter
CRITICALRCERELIABLEWORKING POC
9.9

Grafana Image Renderer is vulnerable to remote code execution due to an arbitrary file write vulnerability. This is due to the fact that the /render/csv endpoint lacked validation of the filePath parameter that allowed an attacker to save a shared object to an arbitrary location that is then...

PythonTRIVIAL
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-11539-vulnerable:latest
CVE-2025-11539 lab
CVE-2025-58046 Dataease <= 2.10.12 - Remote Code Execution via Impala JDBC Connection String JNDI Injection
CRITICALRCERELIABLEWORKING POC
9.8

Dataease is an open-source data visualization and analysis platform. In versions up to and including 2.10.12, the Impala data source is vulnerable to remote code execution due to insufficient filtering in the getJdbc method of the io.dataease.datasource.type.Impala class. Attackers can construct...

PythonMODERATE
Docker Images
mysql docker pull ghcr.io/exploitintel/cve-2025-58046-mysql:latest
patched docker pull ghcr.io/exploitintel/cve-2025-58046-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-58046-vulnerable:latest
CVE-2025-58046 lab
CVE-2024-43115 Apache DolphinScheduler <3.2.2 - RCE
HIGHRCERELIABLEWORKING POC
8.8

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which fixes the issue.

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2024-43115-vulnerable:latest
CVE-2024-43115 lab
CVE-2025-58159 WeGIA < 3.4.11 - Remote Code Execution via Unrestricted PHP File Upload
CRITICALRCERELIABLEWORKING POC
9.9

WeGIA is a Web manager for charitable institutions. Prior to version 3.4.11, a remote code execution vulnerability was identified, caused by improper validation of uploaded files. The application allows an attacker to upload files with arbitrary filenames, including those with a .php extension....

PythonMODERATE
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2025-58159-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-58159-vulnerable:latest
CVE-2025-58159 lab
CVE-2025-53192 Apache Commons OGNL - Code Injection
HIGHRCERELIABLEWORKING POC
8.8

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons OGNL. This issue affects Apache Commons OGNL: all versions. When using the API Ognl.getValue​, the OGNL engine parses and evaluates the provided expression with powerful...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-53192-vulnerable:latest
CVE-2025-53192 lab
CVE-2025-54466 Apache OFBiz < 24.09.02 - Unauthenticated Remote Code Execution via Scrum Plugin
CRITICALRCERELIABLEWORKING POC
9.8

Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Apache OFBiz: before 24.09.02 only when the scrum plugin is used. Even unauthenticated attackers can exploit this vulnerability. Users are...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-54466-vulnerable:latest
CVE-2025-54466 lab
CVE-2025-7734 GitLab CE/EE <18.0.6-18.2.2 - Code Injection
HIGHXSSRELIABLEWORKING POC
8.7

An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2 before 18.2.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-7734-vulnerable:latest
CVE-2025-7734 lab
CVE-2025-55010 Kanboard <1.2.47 - Remote Code Execution
CRITICALRCERELIABLEWORKING POC
9.1

Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, an unsafe deserialization vulnerability in the ProjectEventActvityFormatter allows admin users the ability to instantiate arbitrary php objects by modifying the event["data"] field in the...

PythonMODERATE
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2025-55010-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-55010-vulnerable:latest
CVE-2025-55010 lab
CVE-2025-48913 Apache CXF < 3.6.8 - Remote Code Execution via JMS Configuration
CRITICALSSRFRELIABLEWORKING POC
9.8

If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility. Users are recommended to upgrade to versions...

PythonMODERATE
Docker Images
attacker docker pull ghcr.io/exploitintel/cve-2025-48913-attacker:latest
patched docker pull ghcr.io/exploitintel/cve-2025-48913-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-48913-vulnerable:latest
Docker Lab
CVE-2025-53606 Apache Seata <2.5.0 - Deserialization
CRITICALDESERIALIZATIONRELIABLEWORKING POC
9.8

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): 2.4.0. Users are recommended to upgrade to version 2.5.0, which fixes the issue.

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-53606-vulnerable:latest
CVE-2025-53606 lab
CVE-2025-6000 HashiCorp Vault 0.8.0-1.16.22, 1.17.0-1.19.6, 1.20.0 - Authenticated RCE via Plugin Directory
CRITICALRCERELIABLEWORKING POC
9.1

A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plugin directory is set in Vault’s configuration. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-6000-vulnerable:latest
CVE-2025-6000 lab
CVE-2025-49828 Conjur 1.19.5-1.21.1 and 13.1-13.4.1 - Authenticated Remote Code Execution via Template Injection
HIGHRCERELIABLEWORKING POC
8.8

Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.21.1 and Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.1 through 13.4.1 are vulnerable to remote code execution An authenticated attacker who can inject...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-49828-vulnerable:latest
CVE-2025-49828 lab
CVE-2025-53833 LaRecipe < 2.8.1 - Server-Side Template Injection
CRITICALRCERELIABLEWORKING POC
10.0

LaRecipe is an application that allows users to create documentation with Markdown inside a Laravel app. Versions prior to 2.8.1 are vulnerable to Server-Side Template Injection (SSTI), which could potentially lead to Remote Code Execution (RCE) in vulnerable configurations. Attackers could...

PythonMODERATE
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2025-53833-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-53833-vulnerable:latest
CVE-2025-53833 lab
CVE-2025-32897 Apache Seata 2.0.0-2.3.0 - Deserialization of Untrusted Data in Raft Cluster Mode
CRITICALRCERELIABLEWORKING POC
9.8

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This security vulnerability is the same as CVE-2024-47552, but the version range described in the CVE-2024-47552 definition is too narrow. This issue affects Apache Seata (incubating): from 2.0.0 before...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-32897-vulnerable:latest
CVE-2025-32897 lab
CVE-2025-50213 Apache Airflow Providers Snowflake <6.4.0 - Special Element Injection
CRITICALSQLIRELIABLEWORKING POC
9.8

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This issue affects Apache Airflow Providers Snowflake: before 6.4.0. Sanitation of table and stage parameters were added...

PythonMODERATE
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2025-50213-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-50213-vulnerable:latest
Docker Lab
CVE-2025-4981 Mattermost <=10.5.5, <=9.11.15, <=10.8.0, <=10.7.2, <=10.6.5 - Authenticated Arbitrary File Write via Path Traversal
CRITICALOTHERRELIABLEWORKING POC
9.9

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in the archive extractor which allows authenticated users to write files to arbitrary locations on the filesystem via uploading archives with path traversal...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-4981-vulnerable:latest
CVE-2025-4981 lab
CVE-2025-27818 Apache Kafka 2.3.0-3.9.0 - Authenticated Remote Code Execution via SASL JAAS LDAP Deserialization
HIGHRCERELIABLEWORKING POC
8.8

A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS config and a SASL-based security protocol,...

PythonMODERATE
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2025-27818-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-27818-vulnerable:latest
CVE-2025-27818 lab
CVE-2025-27531 Apache InLong <2.1.0 - Deserialization
CRITICALDESERIALIZATIONRELIABLEWORKING POC
9.8

Deserialization of Untrusted Data vulnerability in Apache InLong.  This issue affects Apache InLong: from 1.13.0 before 2.1.0, this issue would allow an authenticated attacker to read arbitrary files by double writing the param. Users are recommended to upgrade to version 2.1.0, which...

PythonMODERATE
Docker Images
mysql docker pull ghcr.io/exploitintel/cve-2025-27531-mysql:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-27531-vulnerable:latest
CVE-2025-27531 lab
CVE-2025-47916 Invisioncommunity < 5.0.7 - Remote Code Execution
CRITICALRCERELIABLEWORKING POC
10.0

Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeeditor controller (file: /applications/core/modules/front/system/themeeditor.php), where a protected method named customCss can be invoked by...

PythonTRIVIAL
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2025-47916-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-47916-vulnerable:latest
CVE-2025-47916 lab
CVE-2025-29953 Apache ActiveMQ NMS OpenWire Client <2.1.1 - Deserialization
CRITICALDESERIALIZATIONRELIABLEWORKING POC
9.8

Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client. This issue affects Apache ActiveMQ NMS OpenWire Client before 2.1.1 when performing connections to untrusted servers. Such servers could abuse the unbounded deserialization in the client to provide malicious...

PythonMODERATE
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2025-29953-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-29953-vulnerable:latest
CVE-2025-29953 lab
CVE-2024-56325 Apache Pinot < 1.3.0 - Authentication Bypass via Path Manipulation
CRITICALAUTH BYPASSRELIABLEWORKING POC
9.8

Authentication Bypass Issue If the path does not contain / and contain., authentication is not required. Expected Normal Request and Response Example curl -X POST -H "Content-Type: application/json" -d...

CTRIVIAL
Docker Images
broker docker pull ghcr.io/exploitintel/cve-2024-56325-broker:latest
Docker Lab
CVE-2025-2753 Open Asset Import Library Assimp 5.4.3 - Out-of-Bounds Read in LWS File Handler
MEDIUMDOSRELIABLEWORKING POC
6.3

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as critical. Affected is the function SceneCombiner::MergeScenes of the file code/AssetLib/LWS/LWSLoader.cpp of the component LWS File Handler. The manipulation leads to out-of-bounds read. It is possible...

PythonMODERATE
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2025-2753-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-2753-vulnerable:latest
Docker Lab
CVE-2025-29927 Next.js Middleware Bypass
CRITICALAUTH BYPASSRELIABLEWORKING POC
9.1

Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware. If patching to...

PythonTRIVIAL
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-29927-vulnerable:latest
CVE-2025-29927 lab
CVE-2025-24490 Mattermost 9.11.0-9.11.7, 10.2.0-10.2.2, 10.3.0-10.3.2, 10.4.0-10.4.1 - SQL Injection via Boards Reordering
CRITICALSQLIRELIABLEWORKING POC
9.6

Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to use prepared statements in the SQL query of boards reordering which allows an attacker to retrieve data from the database, via a SQL injection when reordering specially crafted boards categories.

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-24490-vulnerable:latest
CVE-2025-24490 lab
CVE-2024-45409 ruby-saml <=1.12.2 and 1.13.0-1.16.0 - Unauthenticated SAML Signature Verification Bypass
CRITICALAUTH BYPASSRELIABLEWORKING POC
10.0

The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed saml document (by the IdP) can thus forge a SAML...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2024-45409-vulnerable:latest
CVE-2024-45409 lab
CVE-2024-37288 Kibana - Remote Code Execution via YAML Deserialization in AI Tools Amazon Bedrock Connector
CRITICALRCERELIABLEWORKING POC
9.9

A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. This issue only affects users that use Elastic Security’s built-in AI tools https://www.elastic.co/guide/en/security/current/ai-for-security.html...

PythonMODERATE
Docker Images
kibana docker pull ghcr.io/exploitintel/cve-2024-37288-kibana:latest
CVE-2024-37288 lab
CVE-2023-42117 Exim < 4.96.2 - Unauthenticated Remote Code Execution via SMTP Service
CRITICALDOSRELIABLEWORKING POC
9.8

Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp...

PythonTRIVIAL
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2023-42117-vulnerable:latest
Docker Lab
CVE-2024-31866 Apache Zeppelin 0.8.2-0.11.0 - Remote Code Execution via Configuration Override
CRITICALRCERELIABLEWORKING POC
9.8

Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can execute shell scripts or malicious code by overriding configuration like ZEPPELIN_INTP_CLASSPATH_OVERRIDES. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2024-31866-vulnerable:latest
CVE-2024-31866 lab
CVE-2021-32824 Apache Dubbo < 2.6.10 - Unauthenticated Remote Code Execution via Telnet Handler Bean Manipulation
CRITICALRCERELIABLEWORKING POC
9.8

Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arbitrary bean manipulation in the Telnet handler. The Dubbo main service port can be used to access a Telnet Handler which offers some basic methods...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2021-32824-vulnerable:latest
Docker Lab

Community Labs
573
Discovered from GitHub exploit repositories with Dockerfiles