
railsgoat
A vulnerable version of Rails that follows the OWASP Top 10

A vulnerable version of Rails that follows the OWASP Top 10

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…

A deliberately vulnerable web application for learning web application security.

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

Vulnerable app with examples showing how to not use secrets

The Secure Coding Dojo is a platform for delivering secure coding knowledge.

Host and manage multiple Juice Shop instances for security trainings and Capture The Flags

A collection of hacking / penetration testing resources to make you better!

😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing.

A collection of awesome platforms, blogs, documents, books, resources and cool stuff about security

Some good resources for getting started with application security

Open-source AI security benchmarking CLI. Measure how AI models perform offensive security tasks with MITRE ATT&CK analysis and KSM scoring.

An OWASP-aligned intentionally vulnerable platform for learning and testing AI, LLM, RAG, MCP, and Agentic AI security.

Open-source prompt injection attack console. Test AI security by firing categorized attacks at any endpoint.

Comprehensive Java vulnerability lab with vulnerable and fixed code, attack scenarios, source/sink audit notes, and secure coding guidance for…

OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS

Hands-on AI security learning platform with intentionally vulnerable LLM applications. Explore OWASP Top 10 for LLMs through interactive pizza shop…