CVE Labs & Environments

The largest open collection of weaponized CVE lab environments on the internet. Spin up a vulnerable target, pop a shell, verify the patch - in seconds. Every EIP lab ships with working proof-of-concept exploit code, vulnerable and patched multi-arch Docker images, and full AI-driven analysis covering root cause, attack surface, and verified remediation. Community labs extend coverage with thousands of additional environments discovered from open-source exploit repositories across GitHub.

GitHub · API

644 Total Labs
66 EIP Labs
578 Community
87 EIP Images
1544 Community Images
28 Critical
11 High
2 Medium
EIP Labs
66
CVEForge-authored · Full analysis · Multi-arch Docker images
CVE-2025-59060 Apache Ranger <=2.7.0 - Auth Bypass
MEDIUMAUTH BYPASSRELIABLEWORKING POC
5.3

Hostname verification bypass issue in Apache Ranger NiFiRegistryClient/NiFiClient is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue.

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-59060-vulnerable:latest
CVE-2025-59060 lab
CVE-2025-69985 FUXA <=1.2.8 - Auth Bypass to RCE
CRITICALRCERELIABLEWORKING POC
9.8

FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts the HTTP "Referer" header to validate internal requests. A remote unauthenticated attacker can...

PythonTRIVIAL
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2025-69985-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-69985-vulnerable:latest
CVE-2025-69985 lab
CVE-2025-15467 Openssl < 3.0.19 - Out-of-Bounds Write
HIGHRCERELIABLEWORKING POC
8.8

Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS...

PythonCOMPLEX
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-15467-vulnerable:latest
Docker Lab
CVE-2016-15057 Apache Continuum - Command Injection
CRITICALRCERELIABLEWORKING POC
9.9

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Continuum. This issue affects Apache Continuum: all versions. Attackers with access to the installations REST API can use this to invoke arbitrary...

PythonTRIVIAL
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2016-15057-vulnerable:latest
CVE-2016-15057 lab
CVE-2025-66524 Apache NiFi <2.6.0 - Deserialization
HIGHDESERIALIZATIONRELIABLEWORKING POC
8.8

Apache NiFi 1.20.0 through 2.6.0 include the GetAsanaObject Processor, which requires integration with a configurable Distribute Map Cache Client Service for storing and retrieving state information. The GetAsanaObject Processor used generic Java Object serialization and deserialization without...

PythonMODERATE
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2025-66524-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-66524-vulnerable:latest
Docker Lab
CVE-2025-67895 Apache-airflow-providers-edge3 < 2.0.0 - Remote Code Execution
CRITICALRCERELIABLEWORKING POC
9.8

Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you installed and configured it on Airflow 2. The Edge3 provider support in Airflow 2 has been always development-only and not officially released, however if you installed and...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-67895-vulnerable:latest
CVE-2025-67895 lab
CVE-2025-26866 Apache Hugegraph < 1.7.0 - Insecure Deserialization
HIGHRCERELIABLEWORKING POC
8.8

A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces IP-based authentication to restrict cluster membership and implements a strict class whitelist to harden the Hessian serialization process...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-26866-vulnerable:latest
CVE-2025-26866 lab
CVE-2025-66489 Cal.com <5.9.8 - Auth Bypass
CRITICALAUTH BYPASSRELIABLEWORKING POC
9.8

Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker to bypass password verification when a TOTP code is provided, potentially gaining unauthorized access to user accounts. This issue exists due to problematic conditional logic...

PythonTRIVIAL
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-66489-vulnerable:latest
CVE-2025-66489 lab
CVE-2025-12421 Mattermost <11.0.2, 10.12.1, 10.11.4, 10.5.12 - Auth Bypass
CRITICALAUTH BYPASSRELIABLEWORKING POC
9.9

Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-12421-vulnerable:latest
CVE-2025-12421 lab
CVE-2025-59390 Apache Druid < 35.0.0 - Authentication Bypass
CRITICALAUTH BYPASSRELIABLEWORKING POC
9.8

Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is not explicitly set. In this case, the secret is generated using `ThreadLocalRandom`, which is not a crypto-graphically secure random number...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-59390-vulnerable:latest
CVE-2025-59390 lab
CVE-2025-10622 Red Hat Satellite - Command Injection
HIGHRCERELIABLEWORKING POC
8.0

A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_settings permissions to achieve arbitrary command execution on the underlying operating system via insufficient server-side validation of command whitelisting.

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-10622-vulnerable:latest
CVE-2025-10622 lab
CVE-2025-62507 Redis < 8.2.3 - Out-of-Bounds Write
HIGHRCERELIABLEWORKING POC
8.8

Redis is an open source, in-memory database that persists on disk. In versions 8.2.0 and above, a user can run the XACKDEL command with multiple ID's and trigger a stack buffer overflow, which may potentially lead to remote code execution. This issue is fixed in version 8.2.3. To workaround this...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-62507-vulnerable:latest
Docker Lab
CVE-2025-62515 Pypi Pyquokka - Insecure Deserialization
CRITICALRCERELIABLEWORKING POC
9.8

pyquokka is a framework for making data lakes work for time series. In versions 0.3.1 and prior, the FlightServer class directly uses pickle.loads() to deserialize action bodies received from Flight clients without any sanitization or validation in the do_action() method. The vulnerable code is...

PythonTRIVIAL
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2025-62515-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-62515-vulnerable:latest
Docker Lab
CVE-2024-56143 Strapi < 5.5.2 - IDOR
HIGHINFO LEAKRELIABLEWORKING POC
8.2

Strapi is an open-source headless content management system. In versions from 5.0.0 to before 5.5.2, the lookup operator provided by the document service does not properly sanitize query parameters for private fields. An attacker can access private fields, including admin passwords and reset...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2024-56143-vulnerable:latest
CVE-2024-56143 lab
CVE-2025-11539 Grafana Image Renderer - RCE
CRITICALRCERELIABLEWORKING POC
9.9

Grafana Image Renderer is vulnerable to remote code execution due to an arbitrary file write vulnerability. This is due to the fact that the /render/csv endpoint lacked validation of the filePath parameter that allowed an attacker to save a shared object to an arbitrary location that is then...

PythonTRIVIAL
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-11539-vulnerable:latest
CVE-2025-11539 lab
CVE-2025-58046 Dataease < 2.10.13 - Insecure Deserialization
CRITICALRCERELIABLEWORKING POC
9.8

Dataease is an open-source data visualization and analysis platform. In versions up to and including 2.10.12, the Impala data source is vulnerable to remote code execution due to insufficient filtering in the getJdbc method of the io.dataease.datasource.type.Impala class. Attackers can construct...

PythonMODERATE
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2025-58046-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-58046-vulnerable:latest
CVE-2025-58046 lab
CVE-2024-43115 Apache DolphinScheduler <3.2.2 - RCE
HIGHRCERELIABLEWORKING POC
8.8

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can execute any shell script server by alert script. This issue affects Apache DolphinScheduler: before 3.2.2. Users are recommended to upgrade to version 3.3.1, which fixes the issue.

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2024-43115-vulnerable:latest
CVE-2024-43115 lab
CVE-2025-58159 Wegia < 3.4.11 - Code Injection
CRITICALRCERELIABLEWORKING POC
9.9

WeGIA is a Web manager for charitable institutions. Prior to version 3.4.11, a remote code execution vulnerability was identified, caused by improper validation of uploaded files. The application allows an attacker to upload files with arbitrary filenames, including those with a .php extension....

PythonMODERATE
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2025-58159-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-58159-vulnerable:latest
CVE-2025-58159 lab
CVE-2025-53192 Apache Commons OGNL - Code Injection
HIGHRCERELIABLEWORKING POC
8.8

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Expression/Command Delimiters vulnerability in Apache Commons OGNL. This issue affects Apache Commons OGNL: all versions. When using the API Ognl.getValue​, the OGNL engine parses and evaluates the provided expression with powerful...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-53192-vulnerable:latest
CVE-2025-53192 lab
CVE-2025-54466 Apache Ofbiz < 24.09.02 - Code Injection
CRITICALRCERELIABLEWORKING POC
9.8

Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Apache OFBiz: before 24.09.02 only when the scrum plugin is used. Even unauthenticated attackers can exploit this vulnerability. Users are...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-54466-vulnerable:latest
CVE-2025-54466 lab
CVE-2025-7734 GitLab CE/EE <18.0.6-18.2.2 - Code Injection
HIGHXSSRELIABLEWORKING POC
8.7

An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2 before 18.2.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-7734-vulnerable:latest
CVE-2025-7734 lab
CVE-2025-55010 Kanboard <1.2.47 - Remote Code Execution
CRITICALRCERELIABLEWORKING POC
9.1

Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, an unsafe deserialization vulnerability in the ProjectEventActvityFormatter allows admin users the ability to instantiate arbitrary php objects by modifying the event["data"] field in the...

PythonMODERATE
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2025-55010-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-55010-vulnerable:latest
CVE-2025-55010 lab
CVE-2025-48913 Apache CXF <3.6.8-4.1.3 - RCE
CRITICALSSRFRELIABLEWORKING POC
9.8

If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution capabilities. This interface is now restricted to reject those protocols, removing this possibility. Users are recommended to upgrade to versions...

PythonMODERATE
Docker Images
attacker docker pull ghcr.io/exploitintel/cve-2025-48913-attacker:latest
patched docker pull ghcr.io/exploitintel/cve-2025-48913-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-48913-vulnerable:latest
Docker Lab
CVE-2025-53606 Apache Seata <2.5.0 - Deserialization
CRITICALDESERIALIZATIONRELIABLEWORKING POC
9.8

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): 2.4.0. Users are recommended to upgrade to version 2.5.0, which fixes the issue.

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-53606-vulnerable:latest
CVE-2025-53606 lab
CVE-2025-6000 Vault <1.20.1 - Code Injection
CRITICALRCERELIABLEWORKING POC
9.1

A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plugin directory is set in Vault’s configuration. Fixed in Vault Community Edition 1.20.1 and Vault Enterprise 1.20.1, 1.19.7, 1.18.12, and 1.16.23.

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-6000-vulnerable:latest
CVE-2025-6000 lab
CVE-2025-49828 Cyberark Conjur < 1.21.2 - Remote Code Execution
HIGHRCERELIABLEWORKING POC
8.8

Conjur provides secrets management and application identity for infrastructure. Conjur OSS versions 1.19.5 through 1.21.1 and Secrets Manager, Self-Hosted (formerly known as Conjur Enterprise) 13.1 through 13.4.1 are vulnerable to remote code execution An authenticated attacker who can inject...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-49828-vulnerable:latest
CVE-2025-49828 lab
CVE-2025-53833 LaRecipe <2.8.1 - SSRF/RCE
CRITICALRCERELIABLEWORKING POC
10.0

LaRecipe is an application that allows users to create documentation with Markdown inside a Laravel app. Versions prior to 2.8.1 are vulnerable to Server-Side Template Injection (SSTI), which could potentially lead to Remote Code Execution (RCE) in vulnerable configurations. Attackers could...

PythonMODERATE
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2025-53833-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-53833-vulnerable:latest
CVE-2025-53833 lab
CVE-2025-32897 Apache Seata < 2.3.0 - Insecure Deserialization
CRITICALRCERELIABLEWORKING POC
9.8

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This security vulnerability is the same as CVE-2024-47552, but the version range described in the CVE-2024-47552 definition is too narrow. This issue affects Apache Seata (incubating): from 2.0.0 before...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-32897-vulnerable:latest
CVE-2025-32897 lab
CVE-2025-50213 Apache Airflow Providers Snowflake <6.4.0 - Special Element Injection
CRITICALSQLIRELIABLEWORKING POC
9.8

Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This issue affects Apache Airflow Providers Snowflake: before 6.4.0. Sanitation of table and stage parameters were added...

PythonMODERATE
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2025-50213-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-50213-vulnerable:latest
Docker Lab
CVE-2025-4981 Mattermost Server < 9.11.16 - Uncontrolled Search Path
CRITICALOTHERRELIABLEWORKING POC
9.9

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in the archive extractor which allows authenticated users to write files to arbitrary locations on the filesystem via uploading archives with path traversal...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-4981-vulnerable:latest
CVE-2025-4981 lab
CVE-2025-27818 Apache Kafka < 3.9.1 - Insecure Deserialization
HIGHRCERELIABLEWORKING POC
8.8

A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS config and a SASL-based security protocol,...

PythonMODERATE
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2025-27818-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-27818-vulnerable:latest
CVE-2025-27818 lab
CVE-2025-27531 Apache InLong <2.1.0 - Deserialization
CRITICALDESERIALIZATIONRELIABLEWORKING POC
9.8

Deserialization of Untrusted Data vulnerability in Apache InLong.  This issue affects Apache InLong: from 1.13.0 before 2.1.0, this issue would allow an authenticated attacker to read arbitrary files by double writing the param. Users are recommended to upgrade to version 2.1.0, which...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-27531-vulnerable:latest
CVE-2025-27531 lab
CVE-2025-47916 Invisioncommunity < 5.0.7 - Remote Code Execution
CRITICALRCERELIABLEWORKING POC
10.0

Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeeditor controller (file: /applications/core/modules/front/system/themeeditor.php), where a protected method named customCss can be invoked by...

PythonTRIVIAL
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2025-47916-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-47916-vulnerable:latest
CVE-2025-47916 lab
CVE-2025-29953 Apache ActiveMQ NMS OpenWire Client <2.1.1 - Deserialization
CRITICALDESERIALIZATIONRELIABLEWORKING POC
9.8

Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client. This issue affects Apache ActiveMQ NMS OpenWire Client before 2.1.1 when performing connections to untrusted servers. Such servers could abuse the unbounded deserialization in the client to provide malicious...

PythonMODERATE
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2025-29953-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-29953-vulnerable:latest
CVE-2025-29953 lab
CVE-2025-2753 Assimp - Memory Corruption
MEDIUMDOSRELIABLEWORKING POC
6.3

A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as critical. Affected is the function SceneCombiner::MergeScenes of the file code/AssetLib/LWS/LWSLoader.cpp of the component LWS File Handler. The manipulation leads to out-of-bounds read. It is possible...

PythonMODERATE
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2025-2753-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2025-2753-vulnerable:latest
Docker Lab
CVE-2025-29927 Next.js Middleware Bypass
CRITICALAUTH BYPASSRELIABLEWORKING POC
9.1

Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 15.2.3, it is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware. If patching to...

PythonTRIVIAL
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-29927-vulnerable:latest
CVE-2025-29927 lab
CVE-2025-24490 Mattermost Server < 9.11.8 - SQL Injection
CRITICALSQLIRELIABLEWORKING POC
9.6

Mattermost versions 10.4.x <= 10.4.1, 9.11.x <= 9.11.7, 10.3.x <= 10.3.2, 10.2.x <= 10.2.2 fail to use prepared statements in the SQL query of boards reordering which allows an attacker to retrieve data from the database, via a SQL injection when reordering specially crafted boards categories.

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2025-24490-vulnerable:latest
CVE-2025-24490 lab
CVE-2024-45409 Ruby-SAML <=1.16.0 - Auth Bypass
CRITICALAUTH BYPASSRELIABLEWORKING POC
10.0

The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed saml document (by the IdP) can thus forge a SAML...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2024-45409-vulnerable:latest
CVE-2024-45409 lab
CVE-2023-42117 Exim < 4.96.2 - Remote Code Execution
CRITICALDOSRELIABLEWORKING POC
9.8

Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp...

PythonTRIVIAL
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2023-42117-vulnerable:latest
Docker Lab
CVE-2024-31866 Apache Zeppelin <0.11.1 - RCE
CRITICALRCERELIABLEWORKING POC
9.8

Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can execute shell scripts or malicious code by overriding configuration like ZEPPELIN_INTP_CLASSPATH_OVERRIDES. This issue affects Apache Zeppelin: from 0.8.2 before 0.11.1. Users are recommended to upgrade...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2024-31866-vulnerable:latest
CVE-2024-31866 lab
CVE-2021-32824 Apache Dubbo <2.6.10-2.7.10 - RCE
CRITICALRCERELIABLEWORKING POC
9.8

Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arbitrary bean manipulation in the Telnet handler. The Dubbo main service port can be used to access a Telnet Handler which offers some basic methods...

PythonMODERATE
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2021-32824-vulnerable:latest
Docker Lab
CVE-2026-0760
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-0760-vulnerable:latest
CVE-2026-0760 lab
CVE-2026-0761
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2026-0761-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2026-0761-vulnerable:latest
CVE-2026-0761 lab
CVE-2026-0765
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-0765-vulnerable:latest
CVE-2026-0765 lab
CVE-2026-0766
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-0766-vulnerable:latest
CVE-2026-0766 lab
CVE-2026-0768
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-0768-vulnerable:latest
CVE-2026-0768 lab
CVE-2026-0769
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-0769-vulnerable:latest
CVE-2026-0769 lab
CVE-2026-0773
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-0773-vulnerable:latest
CVE-2026-0773 lab
CVE-2026-1868
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-1868-vulnerable:latest
CVE-2026-1868 lab
CVE-2026-26321
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-26321-vulnerable:latest
CVE-2026-26321 lab
CVE-2026-2635
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2026-2635-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2026-2635-vulnerable:latest
CVE-2026-2635 lab
CVE-2026-26988
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2026-26988-patched:latest
CVE-2026-26988 lab
CVE-2026-2749
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-2749-vulnerable:latest
CVE-2026-2749 lab
CVE-2026-28215
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-28215-vulnerable:latest
CVE-2026-28215 lab
CVE-2026-28268
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-28268-vulnerable:latest
CVE-2026-28268 lab
CVE-2026-28370
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2026-28370-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2026-28370-vulnerable:latest
CVE-2026-28370 lab
CVE-2026-28372
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-28372-vulnerable:latest
CVE-2026-28372 lab
CVE-2026-28391
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-28391-vulnerable:latest
CVE-2026-28391 lab
CVE-2026-28409
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2026-28409-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2026-28409-vulnerable:latest
CVE-2026-28409 lab
CVE-2026-28417
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-28417-vulnerable:latest
CVE-2026-28417 lab
CVE-2026-30860
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-30860-vulnerable:latest
CVE-2026-30860 lab
CVE-2026-30861
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-30861-vulnerable:latest
CVE-2026-30861 lab
CVE-2026-33765
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2026-33765-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2026-33765-vulnerable:latest
CVE-2026-33765 lab
CVE-2026-34980
Docker Images
vulnerable docker pull ghcr.io/exploitintel/cve-2026-34980-vulnerable:latest
Docker Lab
CVE-2026-35414
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2026-35414-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2026-35414-vulnerable:latest
Docker Lab
CVE-2026-4105
Docker Images
patched docker pull ghcr.io/exploitintel/cve-2026-4105-patched:latest
vulnerable docker pull ghcr.io/exploitintel/cve-2026-4105-vulnerable:latest
CVE-2026-4105 lab

Community Labs
578
Discovered from GitHub exploit repositories with Dockerfiles