Lab involving Shellshock exploitation, quite interesting
SSRF with filter bypass via open redirection vulnerability | Practitioner
SSRF with blacklist-based input filter | Expert
Very specific Expert lab using embed credentials, might worth reviewing