Vulhub

Vulhub is an open-source collection of pre-built vulnerable docker environments for security researchers and educators.

- Stars- Forks0 Environments
# Clone the repository
git clone --depth 1 https://github.com/vulhub/vulhub.git

# Enter the directory
cd vulhub/spring/CVE-2022-22947

# Start the environment
docker compose up -d

Why Use Vulhub?

Docker Based

All environments are built with Docker and Docker Compose, making them easy to deploy and isolate.

Real Vulnerabilities

Practice with real-world vulnerabilities in a safe, controlled environment for learning and research.

Well Documented

Each vulnerability comes with detailed documentation explaining the vulnerability and exploitation steps.

Latest Environments

View all environments
Auth BypassRCEEnvironment Injection
Created 8 days ago

GNU InetUtils telnetd Argument Injection Authentication Bypass

Explore the GNU InetUtils telnetd Argument Injection Authentication Bypass vulnerability and learn how to exploit it.

Learn more
CVE-2026-24061
RCECMS
Created 18 days ago

CraftCMS Yii Class Injection Remote Code Execution

Explore the CraftCMS Yii Class Injection Remote Code Execution vulnerability and learn how to exploit it.

Learn more
CVE-2025-32432
RCEFramework
Created 22 days ago

Livewire Component Property Hydration Remote Code Execution

Explore the Livewire Component Property Hydration Remote Code Execution vulnerability and learn how to exploit it.

Learn more
CVE-2025-54068
RCE
Created 2 months ago

pgAdmin4 <= 9.10 Database Restore Tool Command Injection

Explore the pgAdmin4 <= 9.10 Database Restore Tool Command Injection vulnerability and learn how to exploit it.

Learn more
CVE-2025-13780
RCEDeserializationFramework
Created 2 months ago

React Server Components Flight Protocol Deserialization RCE

Explore the React Server Components Flight Protocol Deserialization RCE vulnerability and learn how to exploit it.

Learn more
CVE-2025-55182
RCE
Created 5 months ago

pgAdmin4 <= 9.1 Authenticated Remote Code Execution

Explore the pgAdmin4 <= 9.1 Authenticated Remote Code Execution vulnerability and learn how to exploit it.

Learn more
CVE-2025-2945

Ready to start your security research?

Explore our collection of vulnerable environments and enhance your security skills today.