
WebGoat
Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Vulnerable app with examples showing how to not use secrets

Atomic web vulnerability labs. One OWASP flaw per app — minimal Flask + Docker, intentionally broken for hands-on study with Burp Suite.

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

A vulnerable version of Rails that follows the OWASP Top 10

Source code for the Binaries of OWASP WrongSecrets

A collection of hacking / penetration testing resources to make you better!

DonkAI is a hands-on lab for the OWASP Top 10 for LLM Applications (2025) - no real LLM required.

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Some good resources for getting started with application security

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

Hack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.

😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing.

Web and mobile application security training platform

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

AI security agent that runs in your terminal, orchestrating local tools, runbooks, and agents for authorized AppSec, pentest, OSINT, and CTF…

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security