Vulhub

Vulhub is an open-source collection of pre-built vulnerable docker environments for security researchers and educators.

- Stars- Forks0 Environments
# Clone the repository
git clone --depth 1 https://github.com/vulhub/vulhub.git

# Enter the directory
cd vulhub/spring/CVE-2022-22947

# Start the environment
docker compose up -d

Why Use Vulhub?

Docker Based

All environments are built with Docker and Docker Compose, making them easy to deploy and isolate.

Real Vulnerabilities

Practice with real-world vulnerabilities in a safe, controlled environment for learning and research.

Well Documented

Each vulnerability comes with detailed documentation explaining the vulnerability and exploitation steps.

Latest Environments

View all environments
RCE
Created 13 hours ago

Gotenberg 8.30.1 ExifTool Argument Injection via PDF Metadata Values

Explore the Gotenberg 8.30.1 ExifTool Argument Injection via PDF Metadata Values vulnerability and learn how to exploit it.

Learn more
CVE-2026-40281
Info DisclosurePath Traversal
Created 2 days ago

GitLab Unauthenticated Arbitrary Local File Read

Explore the GitLab Unauthenticated Arbitrary Local File Read vulnerability and learn how to exploit it.

Learn more
CVE-2026-85706
LLMRCE
Created 3 days ago

Langflow Public Flow Build API Unauthenticated Remote Code Execution

Explore the Langflow Public Flow Build API Unauthenticated Remote Code Execution vulnerability and learn how to exploit it.

Learn more
CVE-2026-33017
RCEDeserialization
Created 2 months ago

Fastjson 1.2.83 Deserialization Remote Command Execution via jar Protocol

Explore the Fastjson 1.2.83 Deserialization Remote Command Execution via jar Protocol vulnerability and learn how to exploit it.

RCESQL InjectionPrivilege EscalationCMS
Created 2 months ago

WordPress Pre-Auth RCE via REST API Batch Route Confusion and SQL Injection (wp2shell)

Explore the WordPress Pre-Auth RCE via REST API Batch Route Confusion and SQL Injection (wp2shell) vulnerability and learn how to exploit it.

Learn more
CVE-2026-63030CVE-2026-60137
Path TraversalInfo DisclosureFramework
Created 5 months ago

Spring Framework Path Traversal via Jetty URI Parsing Inconsistency

Explore the Spring Framework Path Traversal via Jetty URI Parsing Inconsistency vulnerability and learn how to exploit it.

Learn more
CVE-2025-41242

Ready to start your security research?

Explore our collection of vulnerable environments and enhance your security skills today.