
awesome-web-hacking
A list of web application security

A list of web application security

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

A vulnerable version of Rails that follows the OWASP Top 10

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Example exploitable scenarios for CVE-2024-22243 affecting the Spring framework (open redirect & SSRF).

A self-hosted vulnerable Next.js environment running on Docker for simulating CVE-2025-55182. Built for educational security research and CTF…


PoC Docker lab: chaining file upload bypass + stored XSS to create admin accounts. Educational resource for pen testers.