
ModSecurity
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

Application Security Verification Standard

A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying…

Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).

Collection of proof-of-concept exploits and technical analyses for high-impact CVEs, covering browser memory corruption, TCP/IP RCE, and web…

Go Web Application Penetration Test

Deliberately vulnerable Node.js web application for practicing exploitation of SQL injection, XSS, IDOR, command injection, XXE, and deserialization…

OWASP Thick Client Application Security Verification Standard

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

Just another vulnerable web application.

Proof-of-concept exploit for CVE-2023-6875, demonstrating a web application vulnerability. Includes code and instructions for reproducing the issue.

Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security researchers…

Proof-of-concept validation harness for Electron boundary hardening, modeling renderer/main-process isolation, IPC policy enforcement, and navigation…

Proof-of-concept exploit for CVE-2015-9251, demonstrating a specific web application vulnerability with minimal code for testing and verification.

The ZenShare Suite application is vulnerable by a Reflected Cross-Site Scripting (XSS) vulnerability, affecting web application login and recovery…

Vulnerable web application to test CVE-2021-44228 / log4shell and forensic artifacts from an example attack

Dockerized vulnerable web application demonstrating the Log4j CVE-2021-44228 remote code execution vulnerability for educational exploitation and…

Educational lab for exploiting Gitea CVE-2026-20896, focusing on web application vulnerability analysis and penetration testing.