
Damn-Vulnerable-Drone
Damn Vulnerable Drone is an intentionally vulnerable drone hacking simulator based on the popular ArduPilot/MAVLink architecture, providing a…

Damn Vulnerable Drone is an intentionally vulnerable drone hacking simulator based on the popular ArduPilot/MAVLink architecture, providing a…

This is an intentionally vulnerable smart contract truffle deployment aimed at allowing those interested in smart contract security to exploit a wide…

An intentionally vulnerable Android Application to demonstrate various vulnerabilities that airses in Android Components.

Intentionally vulnerable Next.js application demonstrating CVE-2025-55182 RCE via unsafe deserialization in React Server Components. Includes exploit…

Local intentionally vulnerable lab with a guided workshop and CTF challenges for practicing Git push-option RCE, unsafe deserialization,…

Dockerized Spring Boot service intentionally vulnerable to Log4Shell (CVE-2021-44228) for testing detection tools, payloads, and exploit capabilities…

Intentionally vulnerable app for hands-on CVE-2025-64459 practice, enabling guided exploitation and vulnerability analysis in security training.

Intentionally vulnerable Hospital Management System demonstrating SQL injection (CVE-2023-7172) with Docker setup and PoC for educational security…

Intentionally vulnerable Spring app to test CVE-2022-22965

Intentionally vulnerable Next.js environment with PoC exploit and detection templates for CVE-2025-55182 (React2Shell RCE), enabling security testing…

Intentionally vulnerable Next.js app for CVE-2025-55182 security research and CTF challenges

An intentionally vulnerable webapp to get your hands dirty with CVE-2022-42889.

Intentionally vulnerable VM-hosted Java shop — Log4Shell (CVE-2021-44228) workshop lab (EC2 / Azure VM / GCE)

Intentionally vulnerable Next.js environment for testing security scanners against CVE-2025-55182, with PoC exploit and detection guidance.

A Java application intentionally vulnerable to CVE-2021-44228

Sample Spring Boot application intentionally vulnerable to Log4j2 CVE-2021-45105 for practicing exploitation and understanding infinite loop…

Intentionally vulnerable Log4j 2.14.1 HTTP service for hands-on practice with CVE-2021-44228 (Log4Shell) in an isolated sandbox environment.

Intentionally vulnerable CGI lab for Shellshock (CVE-2014-6271) with a Python RFC-3875 server and GNU bash 4.2, designed for isolated security…