
Vulnerable-Web-Application
OWASP Vulnerable Web Application Project https://github.com/hummingbirdscyber

OWASP Vulnerable Web Application Project https://github.com/hummingbirdscyber

Discover hidden debugging parameters and uncover web application secrets

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

Web application vulnerability scanner

FAST WEB APPLICATION VULNERABILITY SCANNER written in python3

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

The Swiss Army knife for automated Web Application Testing

Detect and bypass web application firewalls and protection systems

A wordlist of API names for web application assessments

An intentionally designed broken web application based on REST API.

htcap is a web application scanner able to crawl single page application (SPA) recursively by intercepting ajax calls and DOM changes.

A tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner.

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

Web Application Vulnerability Scanner.

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Apache Struts 2.0 RCE vulnerability - Allows an attacker to inject OS commands into a web application through the content-type header