The labs

CISA Known Exploited Vulnerabilities

The full KEV catalog. Entries marked Validated have been confirmed exploitable by ExploitSynth.

1606

CVEs in catalog

107

Validated

10

Public

For safety reasons, we publicly provide 10 sandboxes with ready-to-run PoCs. Additional environments are available to verified beta users.
10 labs
CVE IDVulnerabilityStatusDate AddedCVSS
CVE-2016-10033

PHPMailer Command Injection Vulnerability

PHP · PHPMailer

Validated
Jul 7, 20259.8
CVE-2025-35939

Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability

Craft CMS · Craft CMS

Validated
Jun 2, 20255.3
CVE-2024-4577

PHP-CGI OS Command Injection Vulnerability

PHP Group · PHP

Validated
Jun 12, 20249.8
CVE-2023-7028

GitLab Community and Enterprise Editions Improper Access Control Vulnerability

GitLab · GitLab CE/EE

Validated
May 1, 202410.0
CVE-2018-15133

Laravel Deserialization of Untrusted Data Vulnerability

Laravel · Laravel Framework

Validated
Jan 16, 20248.1
CVE-2021-39226

Grafana Authentication Bypass Vulnerability

Grafana Labs · Grafana

Validated
Aug 25, 20229.8
CVE-2010-0738

Red Hat JBoss Authentication Bypass Vulnerability

Red Hat · JBoss

Validated
May 25, 20227.5
CVE-2019-10149

Exim Mail Transfer Agent (MTA) Improper Input Validation

Exim · Mail Transfer Agent (MTA)

Validated
Jan 10, 20229.8
CVE-2019-0211

Apache HTTP Server Privilege Escalation Vulnerability

Apache · HTTP Server

Validated
Nov 3, 20217.8
CVE-2020-11651

SaltStack Salt Authentication Bypass Vulnerability

SaltStack · Salt

Validated
Nov 3, 20219.8
CISA KEV catalog preview
CVE-2025-54068

Laravel Livewire Code Injection Vulnerability

Laravel · Livewire

Validated
Mar 20, 2026
CVE-2025-68461

RoundCube Webmail Cross-site Scripting Vulnerability

Roundcube · Webmail

Validated
Feb 20, 2026
CVE-2021-22175

GitLab Server-Side Request Forgery (SSRF) Vulnerability

GitLab · GitLab

Validated
Feb 18, 2026
CVE-2025-64328

Sangoma FreePBX OS Command Injection Vulnerability

Sangoma · FreePBX

Validated
Feb 3, 2026
CVE-2025-68645

Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability

Synacor · Zimbra Collaboration Suite (ZCS)

Validated
Jan 22, 2026
CVE-2025-8110

Gogs Path Traversal Vulnerability

Gogs · Gogs

Validated
Jan 12, 2026
CVE-2025-14847

MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability

MongoDB · MongoDB and MongoDB Server

Validated
Dec 29, 2025
CVE-2025-58360

OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability

OSGeo · GeoServer

Validated
Dec 11, 2025
+1588 more CVEs in the CISA KEV catalog — search to explore

Stay in the loop

Want a specific CVE labbed up?

Drop us your email and the CVE or stack you'd like to see next. We read every message.