
llama_facts
Web application vulnerable to Python3 Flask SSTI (CVE-2019-8341)

Web application vulnerable to Python3 Flask SSTI (CVE-2019-8341)
Challenge based on CVE-2021-22204 where users send a malicious file to a web application to gain RCE

Example exploitable scenarios for CVE-2024-22243 affecting the Spring framework (open redirect & SSRF).

Intentionally vulnerable PHP web app demonstrating SQL injection authentication bypass and unauthorized data disclosure modeled after CVE-2024-8465…

A vulnerable version of Rails that follows the OWASP Top 10

PoC Docker lab: chaining file upload bypass + stored XSS to create admin accounts. Educational resource for pen testers.

Detailed walkthrough of exploiting CVE-2026-29000 in pac4j-jwt to bypass authentication, extract credentials from API settings, and escalate…

Walkthroughs for Capture the Flag challenges on the HTB Cybersecurity Platform.

Web and mobile application security training platform

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

Simple flask application to implement an intentionally vulnerable web app to demo CVE-2023-2822.

Intentionally vulnerable React Server Components lab for studying CVE-2025-55182. Provides a safe environment for security researchers, developers,…

SonicWall security audit toolkit with vulnerable CTF lab (CVE-2021-20038, CVE-2024-53704)

Dockerized lab for training on NGINX rewrite vulnerability (CVE-2026-42945) with vulnerable and patched instances, benign test scripts, and…

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

A curated list of awesome iOS application security resources.

OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS

Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.