
dalfox
Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…


Educational lab simulating CVE-2025-3248 with a vulnerable Docker service and PoC exploit for hands-on security training and mitigation practice.

Local Docker lab reproducing CVE-2026-39987, a pre-auth RCE in marimo's terminal WebSocket. Compares vulnerable and patched versions with least-harm…

Intentionally-vulnerable nginx 1.30.0 CVE lab images (CVE-2026-40701/42934/42945/42946) for isolated security research. Lab use only.

Docker lab to compare vulnerable and patched builds of MCPJam Inspector for CVE-2026-23744, demonstrating network binding differences and API…

Docker-based reproduction of CVE-2017-7529 (Nginx integer overflow) for security testing and education. Part of the Cved vulnerable container…

Docker-based vulnerable environment for practicing CVE-2023-30212 exploitation, featuring an OURPHP web app with a reflected XSS vulnerability for…

Docker-based lab environment for exploiting CVE-2021-42013 (Apache HTTP Server path traversal and RCE) with step-by-step setup instructions for…

CVE-2021-43798 Grafana Unauthenticated Path Traversal - Security Lab | Shivam Gupta | 23104003

Nightingale Docker for Pentesters is a comprehensive Dockerized environment tailored for penetration testing and vulnerability assessment. It comes…

Deliberately vulnerable Docker lab with a routable DNS estate and machine-readable answer keys per target, scoring scanner precision, recall and…

Self-hosted OWASP CTF kit: one box, one free GitHub org, no cloud dependencies

Self-hosted CTF control plane for security-learning events: team registration, live leaderboard, and patch-to-score, quiz, jeopardy, and AI challenge…

A self hosted virtual browser that runs in docker and uses WebRTC.

Offensive Docker is an image with the more used offensive tools to create an environment easily and quickly to launch assessment to the targets.

Bento Toolkit is a minimal fedora-based container for penetration tests and CTF with the sweet addition of GUI applications.

A lab demonstration of the log4shell vulnerability: CVE-2021-44228