
Pegasus-Pentest-Arsenal
A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

a Damn Vulnerable Serverless Application

Deliberately vulnerable C# API application for practicing web application exploitation and security testing. Includes Docker setup and documentation…

An intentionally designed broken web application based on REST API.

A complete bug bounty workspace for HackerOne researchers. Includes scope enforcement, automated recon/vuln pipeline (400+ tools), report templates,…

Damn Vulnerable C# Application (API)

Reproducible A/B lab + safe PoC for GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced)

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

Reproducible BOLA/IDOR PoC against Onlook's tRPC API (CVE-2026-65013), with a 12-step exploit chain, vulnerable and patched Docker targets, and…

Dockerized exploit lab and script for CVE-2026-19478, a critical unauthenticated GitLab GraphQL code injection enabling arbitrary Ruby method calls,…

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…


A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

The code for personally reproducing the corresponding vulnerability

Local Docker lab for reproducing CVE-2026-55255, an IDOR vulnerability in Langflow's Responses API. Validates cross-user flow execution in vulnerable…

CVE-2026-24136 | Lab khai thác lỗ hổng IDOR trên Saleor GraphQL - query order() không kiểm tra xác thực, lộ toàn bộ PII (email, địa chỉ, SĐT) của…

Docker-based lab for reproducing CVE-2026-46645, an authorization bypass in SQLAdmin's ajax_lookup endpoint. Includes vulnerable and patched targets,…