
vuln-bank-mobile
A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

This repository contains an academic and technical analysis of CVE-2023-34362, a critical SQL injection vulnerability affecting the MOVEit Transfer…

An NFC research toolkit application for Android

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

a Damn Vulnerable Serverless Application

Damn Vulnerable C# Application (API)

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

Improper Hostname Verification in EagleEyes Lite Android Application

Improper Certificate Chain Validation in EagleEyes Lite Android Application

The vulnerability exists in the Student Payment API. The application fails to properly validate whether the user requesting a receipt is authorized…

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

Intentionally vulnerable Android banking app for practicing mobile security testing, featuring root detection, anti-debugging, SSL pinning, and…

Public advisory & PoC for CVE-2026-26897 — Deep Link Bypass in EcoOnline EHS Android (com.airsweb.v10), fixed in 0.2.500

Controlled virtual attack & defense lab — CVE-2011-2523 exploitation, Nmap recon, Nikto scanning, UFW hardening on Metasploitable 2

*This project is no longer maintained* OWASP GoatDroid is a fully functional and self-contained training environment for educating developers and…