Labs

All CVE Labs

Every real, disclosed CVE reproduced as a local lab on this site, newest first.

Docker lab RCE

CVE-2026-68771: ComfyUI Unauthenticated RCE via Pickle Deserialization

An unauthenticated upload endpoint and a node that deserializes whatever lands in a folder combine into remote code execution with no login at all.

Docker lab RCE

CVE-2026-65008: Grav CMS Authenticated RCE via Blueprint Callable Injection

What it actually takes to adapt a published PoC when it was written against an admin interface your target doesn't run.

Docker lab RCE

CVE-2026-63720: datamodel-code-generator customBasePath Code Injection RCE

A code generator trusts a schema field enough to paste it, unescaped, into the Python module it writes — and that module runs on import.

Docker lab Account TakeoverSQL Injection

CVE-2026-63030: WordPress Core Pre-Auth Admin Takeover ("wp2shell")

Two chained bugs in WordPress core, no plugin involved, combine into unauthenticated administrator account creation — actively exploited right now.

Docker lab Privilege Escalation

CVE-2026-62183: Apache Syncope Privilege Escalation

A self-service API endpoint in Apache Syncope lets any authenticated user grant themselves admin-level roles.

Docker lab SQL Injection

CVE-2026-60137: WordPress Core author__not_in SQL Injection

WP_Query only integer-casts author__not_in when it arrives as an array — send it as a bare string instead, and whatever follows your closing parenthesis runs as SQL.

Docker lab Account Takeover

CVE-2026-53595: FreeScout Account Takeover

A MySQL trailing-space quirk in a hash comparison is enough to let an attacker take over any FreeScout account, no authentication required.

Docker lab Authentication Bypass

CVE-2026-53591: FreeScout Unauthenticated Conversation Injection

A hash-comparison branch meant only for backward compatibility skips FreeScout's own signature check entirely, letting a guessed thread id and an invalid hash forge a reply into any conversation.

VM lab Privilege Escalation

CVE-2026-53264: Linux Kernel net/sched Use-After-Free

A disposable-VM lab for a real, AI-assisted Linux kernel 0-day — how a use-after-free race in net/sched's traffic-control actions turns an unprivileged shell into root.

Docker lab Information Disclosure

CVE-2026-48812: FreeScout Unauthenticated Attachment Disclosure

A one-line access check that only ever rejects two of three possible token states leaves years of historical attachments on any long-running FreeScout install downloadable by anyone who knows or guesses the URL.

Docker lab Information Disclosure

CVE-2026-45295: FreeScout Open-Tracking Enumeration Oracle

Three HTTP status codes from an unauthenticated tracking-pixel endpoint are enough to enumerate a helpdesk's private conversations and silently corrupt their read-tracking data.

Docker lab RCE

CVE-2026-38165: XDocReport Velocity Template Engine SSTI to RCE

A .docx template gets evaluated as trusted Apache Velocity code with zero sandboxing — reflection reaches Runtime.exec() and the server runs it as root.

Docker lab RCE

CVE-2026-34197: Apache ActiveMQ Jolokia RCE

A JMX management bridge in Apache ActiveMQ turns a single authenticated API call into arbitrary code execution — actively exploited in the wild.

Docker lab Arbitrary File Write

CVE-2026-20253: Splunk Enterprise Unauthenticated File Write Endpoint

A pre-auth endpoint on Splunk's PostgreSQL Sidecar Service returns the exact signature a public detection tool checks for — CVSS 9.8, and real, verifiable signal even without triggering the underlying file write.

Docker lab Arbitrary Method Invocation

CVE-2026-19478: GitLab GraphQL Fallback-Field Arbitrary Method Invocation

An unrecognized GraphQL field name paired with a future-version directive lets an unauthenticated request call any public method on GitLab's own ActiveRecord models.

Docker lab Account Takeover

CVE-2026-15964: Single Sign On For TNG Account Takeover

A password-reset nonce computed identically for every anonymous visitor, then printed straight into the page — turning a public value into full, unauthenticated admin account takeover.

Docker lab SQL Injection

CVE-2026-11349: WordPress Plugin Unauthenticated SQL Injection

Unauthenticated blind SQL injection in the Modern Events Calendar Lite WordPress plugin, with real data actually extracted, not just a proof-of-concept flag.

Docker lab Open Mail Relay

CVE-2026-6675: Responsive Blocks Unauthenticated Open Email Relay

A REST route registered with permission_callback => '__return_true' hands wp_mail() an attacker-chosen recipient, subject, and body — turning any site running the plugin into a free spam relay.

Docker lab SQL Injection

CVE-2026-5813: PHPGurukul Course Registration SQL Injection

A course-availability check drops a raw POST parameter straight into a WHERE clause, unauthenticated, with nothing in front of it — no login page to get past first.

Docker lab Arbitrary File Deletion

CVE-2026-3141: FormGent Unauthenticated Arbitrary File Deletion

A realpath() call on a directory that hasn't been created yet returns false — and a WordPress plugin's own path-traversal guard treats that as proof a request is safe.

Docker lab Price Manipulation

CVE-2026-2519: Bookly Unauthenticated Price Manipulation

A tips field with no floor and no ceiling lets an anonymous visitor book a $100 service for $0.00, verified all the way down to the database row.

Docker lab RCE

CVE-2026-1555: WebStack WordPress Theme Unauthenticated File Upload RCE

The code declares an image-extension allowlist and then never actually checks a file against it — the attacker's own filename decides what lands in the uploads directory.

Docker lab RCE

CVE-2025-68613: n8n Expression Sandbox Escape to Unauthenticated RCE

A workflow-automation platform's JavaScript expression evaluator becomes full remote code execution with no login at all — actively exploited in the wild.

Docker lab RCE

CVE-2025-55182: React Server Components Unauthenticated RCE ("React2Shell")

A maximum-severity CVE — a crafted deserialization payload against React Server Components turns into remote code execution, with output smuggled back through an HTTP redirect header.

Docker lab RCE

CVE-2025-54068: Laravel Livewire Unauthenticated RCE

A component property's type in Livewire's client-state format is all it takes for unauthenticated remote code execution.

Docker lab Session Poisoning

CVE-2025-35939: Craft CMS Unauthenticated Session-File Content Injection

An unauthenticated request writes arbitrary attacker content, unsanitized, into a real PHP session file on disk — a KEV-listed CVE that had no public PoC before this lab.

Docker lab RCE

CVE-2025-24813: Apache Tomcat Session Deserialization RCE

Actively exploited in the wild — two Tomcat misconfigurations combine to let an attacker plant and trigger arbitrary Java deserialization.