
CVE-2026-47101-PoC
The code for personally reproducing the corresponding vulnerability

The code for personally reproducing the corresponding vulnerability

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

a Damn Vulnerable Serverless Application

An intentionally designed broken web application based on REST API.

Damn Vulnerable C# Application (API)

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…




CVE-2026-24136 | Lab khai thác lỗ hổng IDOR trên Saleor GraphQL - query order() không kiểm tra xác thực, lộ toàn bộ PII (email, địa chỉ, SĐT) của…

Detection scanner for CVE-2026-48710 - Host-header auth bypass in Starlette/FastAPI

Reproducible A/B lab + safe PoC for GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced)