
mutillidae
OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…

Containerized lab environment to simulate and exploit CVE-2025-31486, a path traversal vulnerability in Vite's development server, with step-by-step…

Self-contained security training lab reproducing CVE-2026-20253 (Splunk Enterprise unauthenticated RCE). Provides a Docker-based environment to…

CTF lab environment exploiting CVE-2025-55182 (RCE in React Server Components) with vulnerable Next.js blog, detection scripts, and manual exploit…

Web application with vulnerabilities found in real cases, both in pentests and in Bug Bounty programs.

Containerized CTF lab for learning and exploiting CVE-2025-64424, a command injection RCE in Coolify. Includes vulnerable environment, walkthrough,…

Intentionally vulnerable web application for security training, CTF competitions, and testing security tools. Covers OWASP Top Ten vulnerabilities…

Web and mobile application security training platform

WVCTF or WebVulnCTF is a gamified web platform which promotes training in pentesting and web application development security in an entertaining way.…

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

Curated solutions and walkthroughs for PortSwigger Web Security Academy labs, covering web vulnerabilities, JWT attacks, and exploitation techniques…

Intentionally vulnerable React Server Components lab for studying CVE-2025-55182. Provides a safe environment for security researchers, developers,…

Docker Compose wrapper to deploy AperiSite, a curated platform hosting CTF writeups, security challenges, and educational resources covering web,…

Comprehensive Java vulnerability lab with vulnerable and fixed code, attack scenarios, source/sink audit notes, and secure coding guidance for…

Security training for the apps you actually ship. Open your browser and start hacking.

Mountable Rails engine providing 24+ cybersecurity escape room scenarios with randomized passwords, JIT-compiled NPC dialogue, and RESTful API for…

Interactive browser-based lab simulating Chrome memory corruption vulnerabilities (CVE-2025-14765/14766) for safe security training, featuring…

Educational exploit script for CVE-2024-32002 (Git RCE) with automated setup, designed for CTF environments and security training.