
railsgoat
A vulnerable version of Rails that follows the OWASP Top 10

A vulnerable version of Rails that follows the OWASP Top 10

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

A deliberately vulnerable web application for learning web application security.

IoTGoat is a deliberately insecure firmware based on OpenWrt.

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10…

a Damn Vulnerable Serverless Application

Deliberately vulnerable Docker lab with a routable DNS estate and machine-readable answer keys per target, scoring scanner precision, recall and…

Deliberately vulnerable C# API application for practicing web application exploitation and security testing. Includes Docker setup and documentation…

Damn Vulnerable C# Application (API)

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.


The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

An open source threat modeling tool from OWASP