
WSGoat
The vulnerable application that will teach you how to hack WebSockets

The vulnerable application that will teach you how to hack WebSockets

Springboot web application accepts a name get parameter and logs its value to log4j2. Vulnerable to CVE-2021-44228.

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

A curated list of awesome iOS application security resources.

Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security…

The materials of "Hypervisor 101 in Rust", a one-day long course, to quickly learn hardware-assisted virtualization technology and its application…

Demonstrates a padding oracle attack against AES-CBC encryption using a vulnerable Flask decrypt endpoint and a Python exploit script to decrypt…

Example Vulnerable .NET HTTP Remoting

An intentionally-vulnerable GWT-based web application to test tooling and techniques

PoC exploit for CVE-2024-1813: PHP object injection in Simple Job Board WordPress plugin, achieving unauthenticated RCE via gadget chain. Includes…

Educational lab for exploiting Gitea CVE-2026-20896, focusing on web application vulnerability analysis and penetration testing.

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

Defensive NGINX CVE-2026-42533 map regex risk audit with config scanner, Splunk/Defender notes, and lab evidence.

a Damn Vulnerable Serverless Application

Open-source web application security challenge platform with auto-approved registration, SQL dump generation, and Docker deployment for hands-on…

OWASP ServerlessGoat: a serverless application demonstrating common serverless security flaws

A vulnerable version of Rails that follows the OWASP Top 10

Deliberately vulnerable C# API application for practicing web application exploitation and security testing. Includes Docker setup and documentation…