
WebGoat
Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

😎 🔗 Awesome list about all kinds of resources for learning Ethical Hacking and Penetration Testing.

Structured collection of 500+ Hack The Box machine writeups, 400+ challenge solutions, and interactive learning tools including knowledge graphs,…

Deliberately vulnerable Flask web application with 22 security flaws across 3 difficulty levels for hands-on penetration testing and web security…

Deliberately vulnerable Node.js web application containing 19+ security bugs (XSS, SSRF, Prototype Pollution, RCE) for hands-on penetration testing…

Cloud pentesting framework deploying vulnerable-by-demand AWS resources with quest-based scenarios to teach practical penetration testing and…

Elite exploitation toolkit for CVE-2025-55182 (React Server Components RCE). Async polymorphic payloads, advanced WAF/CDN bypass, proxy rotation,…

React2Shell-Exploit — Complete exploitation framework for CVE-2025-55182, including Python exploit, Docker vulnerable lab, Burp Suite manual and…

Proof-of-concept exploit for CVE-2025-55182, demonstrating vulnerability exploitation techniques for educational and penetration testing purposes.

Draft educational security repository for learning vulnerabilities, sandboxing, and secure coding through authorized lab environments such as VMs,…

Curated collection of validated Joomla exploit artifacts with Docker lab environments. Includes RCE, SQLi, XSS, and privilege escalation scripts…

Technical writeup and penetration testing report for CVE-2010-2075, demonstrating UnrealIRCd backdoor exploitation and remediation.

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

Exploit and scanner for CVE-2024-6387 (regreSSHion) in OpenSSH. Includes detection, RCE exploitation, and shellcode generation for authorized…

Educational lab demonstrating the exploitation of CVE-2025-1974, providing hands-on practice for vulnerability analysis and penetration testing.

Educational lab environment for practicing exploitation of CVE-2019-10149 in Exim 4.87, designed for hands-on vulnerability analysis and penetration…

Lab environment for exploiting CVE-2019-0708 (BlueKeep) vulnerability on Kali Linux, providing hands-on practice for penetration testing and…