
CVE-2024-48415
Proof-of-concept for CVE-2024-48415: stored XSS vulnerability in itsourcecode Loan Management System v1.0 via borrower profile fields. Includes…

Proof-of-concept for CVE-2024-48415: stored XSS vulnerability in itsourcecode Loan Management System v1.0 via borrower profile fields. Includes…

*This project is no longer maintained* OWASP GoatDroid is a fully functional and self-contained training environment for educating developers and…

A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10…

A program for testing WAF functionality

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

AzureGoat : A Damn Vulnerable Azure Infrastructure

GCPGoat : A Damn Vulnerable GCP Infrastructure

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

IoTGoat is a deliberately insecure firmware based on OpenWrt.

A structured knowledge base covering AI security fundamentals, threat modeling, red team offensive techniques, and blue team defenses, including LLM…

WordPress security scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

WordPress Verification SMS with TargetSMS Plugin <= 1.5 is vulnerable to Remote Code Execution (RCE)

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

Insecure TeamCity CI environment for hands-on penetration testing training: reconnaissance, credential theft, privilege escalation, and lateral…

An intentionally designed broken web application based on REST API.

Damn Vulnerable C# Application (API)

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.