
redai
AI-driven vulnerability discovery and live validation

AI-driven vulnerability discovery and live validation

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

Intentionally vulnerable Spring app to test CVE-2022-22965

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

Damn Vulnerable Drone is an intentionally vulnerable drone hacking simulator based on the popular ArduPilot/MAVLink architecture, providing a…

Intentionally vulnerable PHP/MariaDB web application for practicing common web security vulnerabilities across multiple difficulty levels in a legal,…

Intentionally vulnerable Kubernetes cluster environment for hands-on security training. Includes 22+ scenarios covering container escape, RBAC…

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

Security training for the apps you actually ship. Open your browser and start hacking.

Intentionally vulnerable Android application.

An intentionally vulnerable Android Application to demonstrate various vulnerabilities that airses in Android Components.

Runs a fleet of intentionally vulnerable web/API apps in isolated Docker stacks for local penetration testing and validating scanner findings with…

Deploy a small, intentionally insecure, vulnerable Windows Domain for RDP Honeypot fully automatically.

Docker-based lab for detecting and exploiting CVE-2025-55182 (React2Shell RCE) in Next.js/React Server Components, with pre-configured vulnerable…

Hands-on AI security learning platform with intentionally vulnerable LLM applications. Explore OWASP Top 10 for LLMs through interactive pizza shop…

An OWASP-aligned intentionally vulnerable platform for learning and testing AI, LLM, RAG, MCP, and Agentic AI security.