
vuln_apps
Runs a fleet of intentionally vulnerable web/API apps in isolated Docker stacks for local penetration testing and validating scanner findings with…

Runs a fleet of intentionally vulnerable web/API apps in isolated Docker stacks for local penetration testing and validating scanner findings with…

Twitter vulnerable snippets

Community-led OSINT verification standard with testable requirements, acceptance tests, JSON schemas, and assessment formats for safer, interoperable…

Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation.…

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

Log4Shell (CVE-2021-44228) defense lab — nginx + Coraza WAF dynamic module + OWASP CRS v4. Educational use only.



a Damn Vulnerable Serverless Application

DonkAI is a hands-on lab for the OWASP Top 10 for LLM Applications (2025) - no real LLM required.

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how…

OWASP Learning Gateway Project

OWASP ServerlessGoat: a serverless application demonstrating common serverless security flaws

VULCONHUB provides access to files to build your own hands-on vulnerable container image to learn and practice security