
cloudfoxable
Create your own vulnerable by design AWS penetration testing playground

Create your own vulnerable by design AWS penetration testing playground

Proof-of-concept exploit for CVE-2024-34070, a stored XSS in Froxlor. Detects vulnerable instances, extracts version, and injects payload to create…

PoC Docker lab: chaining file upload bypass + stored XSS to create admin accounts. Educational resource for pen testers.

Docker-based CTF challenge exploiting CVE-2024-3552 in a web directory plugin. Start with docker-compose up and exploit the vulnerable WordPress-like…

SonicWall security audit toolkit with vulnerable CTF lab (CVE-2021-20038, CVE-2024-53704)

An implementation of a vulnerable MCP server using mcp-go

Proof-of-concept exploit for CVE-2026-49757 demonstrating OAuth2/OIDC account takeover via email-based user matching in AshAuthentication, with…

Exploit for CrushFTP CVE-2025-31161 auth bypass: detects vulnerable targets, enumerates users, and creates unauthorized admin accounts through…

Docker-based CTF lab demonstrating CVE-2024-4577 PHP-CGI argument injection leading to RCE. Includes vulnerable PHP 5.4.1 CGI, exploit scripts, and…

The full repo of all the labs available as part of the benchmark

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

An open source Android application that is intentionally vulnerable so as to act as a learning platform for Android application security beginners.

Deliberately vulnerable client-server application for learning penetration testing of non-HTTP thick clients. Includes challenges for SQL injection,…

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…

CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool

Damn Vulnerable MCP Server