
dynast-bench
A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

Intentionally vulnerable CGI lab for Shellshock (CVE-2014-6271) with a Python RFC-3875 server and GNU bash 4.2, designed for isolated security…

Intentionally vulnerable Drupal 7.57 lab for reproducing CVE-2018-7600 (Drupalgeddon2) in a Docker container, with an installer script and PHP…

Intentionally vulnerable Log4j 2.14.1 HTTP service for hands-on practice with CVE-2021-44228 (Log4Shell) in an isolated sandbox environment.

Intentionally vulnerable Hospital Management System demonstrating SQL injection (CVE-2023-7172) with Docker setup and PoC for educational security…

Intentionally vulnerable Golang programs exposing web, gRPC, and database/sql flaws for security training, vulnerability discovery, and remediation…

Intentionally Vulnerable Serverless Functions to understand the specifics of Serverless Security Vulnerabilities

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

Intentionally vulnerable app for hands-on CVE-2025-64459 practice, enabling guided exploitation and vulnerability analysis in security training.

Runs a fleet of intentionally vulnerable web/API apps in isolated Docker stacks for local penetration testing and validating scanner findings with…

Local intentionally vulnerable lab with a guided workshop and CTF challenges for practicing Git push-option RCE, unsafe deserialization,…

This is an intentionally vulnerable smart contract truffle deployment aimed at allowing those interested in smart contract security to exploit a wide…

Educational examples porting Linux kernel vulnerabilities to Rust, featuring intentionally vulnerable code and exploits for learning kernel security…


This repository contains a number of insecure self-hosted applications that allows interested security engineers to test vulnerabilities found by…

Intentionally vulnerable machine learning model for hands-on security training. Explore common ML vulnerabilities, adversarial attacks, and defensive…

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.