
railsgoat
A vulnerable version of Rails that follows the OWASP Top 10

A vulnerable version of Rails that follows the OWASP Top 10

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

A deliberately vulnerable web application for learning web application security.

IoTGoat is a deliberately insecure firmware based on OpenWrt.

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10…

a Damn Vulnerable Serverless Application

Deliberately vulnerable Docker lab with a routable DNS estate and machine-readable answer keys per target, scoring scanner precision, recall and…

Deliberately vulnerable C# API application for practicing web application exploitation and security testing. Includes Docker setup and documentation…

Damn Vulnerable C# Application (API)

⚠️ This repo is no longer in use. Please refer to https://github.com/OWASP/www-project-vulnerable-web-applications-directory

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

Vulnerable app with examples showing how to not use secrets

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

The Secure Coding Dojo is a platform for delivering secure coding knowledge.
