
GOAD
Automated vulnerable Active Directory lab suite for practicing penetration testing techniques, with prebuilt domains/forests and standalone attack…

Automated vulnerable Active Directory lab suite for practicing penetration testing techniques, with prebuilt domains/forests and standalone attack…

⚔️Windows11 Penetration Suite Toolkit 🔰 The First Windows Penetration Testing Environment on Mac M Chips

React2Shell-Exploit — Complete exploitation framework for CVE-2025-55182, including Python exploit, Docker vulnerable lab, Burp Suite manual and…

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

a Damn Vulnerable Serverless Application

An intentionally designed broken web application based on REST API.

Damn Vulnerable C# Application (API)

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

The code for personally reproducing the corresponding vulnerability




CVE-2026-24136 | Lab khai thác lỗ hổng IDOR trên Saleor GraphQL - query order() không kiểm tra xác thực, lộ toàn bộ PII (email, địa chỉ, SĐT) của…