
Damn-Vulnerable-GraphQL-Application
Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

A vulnerable version of Rails that follows the OWASP Top 10

Deliberately vulnerable Flask web application with 22 security flaws across 3 difficulty levels for hands-on penetration testing and web security…

A step by step workshop to exploit various vulnerabilities in Node.js and Java applications

Deliberately vulnerable Node.js web application containing 19+ security bugs (XSS, SSRF, Prototype Pollution, RCE) for hands-on penetration testing…

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Vulnerability as a service: showcasing CVS-2014-6271, a.k.a. Shellshock


Log4Shell CVE-2021-44228 mitigation tester

WARNING: This is a vulnerable application to test the exploit for the Spring Break vulnerability (CVE-2017-8046). Run it at your own risk!

Proof of Concept Appliction for testing CVE-2022-42889

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

This Repository Includes Kubernetes manifest files for configuration of Honeypot system and Falco IDS in K8s environment. There are also Demo…

A self-hosted vulnerable Next.js environment running on Docker for simulating CVE-2025-55182. Built for educational security research and CTF…


PoC Docker lab: chaining file upload bypass + stored XSS to create admin accounts. Educational resource for pen testers.

The objective is to conduct a full-scale security assessment of a WordPress-based web application, culminating in a complete server compromise. The…

React2Shell (CVE-2025-55182) – An intentionally vulnerable Next.js application created for educational and research purposes.