
PENTEST-LAB
Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

Intentionally vulnerable React Server Components lab for studying CVE-2025-55182. Provides a safe environment for security researchers, developers,…

A curated list of awesome iOS application security resources.

Web application with vulnerabilities found in real cases, both in pentests and in Bug Bounty programs.

Some good resources for getting started with application security

A web application vulnerable to CVE-2020-14343 insecure deserialization leading to command execution in PyYAML package.

Step-by-step walkthrough for exploiting Subrion CMS via CVE-2021-2220 on an OffSec lab machine, covering web application exploitation and flag…

Docker-based lab demonstrating CVE-2017-8291 (GhostButt) exploitation via Python PIL/Pillow EPS image processing, with a vulnerable web application…

Challenge based on CVE-2021-22204 where users send a malicious file to a web application to gain RCE

Web application vulnerable to Python3 Flask SSTI (CVE-2019-8341)

A vulnerable version of Rails that follows the OWASP Top 10

PoC Docker lab: chaining file upload bypass + stored XSS to create admin accounts. Educational resource for pen testers.

SonicWall security audit toolkit with vulnerable CTF lab (CVE-2021-20038, CVE-2024-53704)

Dockerized lab for training on NGINX rewrite vulnerability (CVE-2026-42945) with vulnerable and patched instances, benign test scripts, and…

Intentionally vulnerable Next.js app for CVE-2025-55182 security research and CTF challenges

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

Simple flask application to implement an intentionally vulnerable web app to demo CVE-2023-2822.

Intentionally vulnerable Next.js application demonstrating CVE-2025-29927 middleware authorization bypass, designed for security testing and…