
JavaScript-Example
Seal Security example — vulnerable npm app (EJS CVE-2022-29078) remediated to sealed versions; GitHub Actions + Jenkins integration

Seal Security example — vulnerable npm app (EJS CVE-2022-29078) remediated to sealed versions; GitHub Actions + Jenkins integration

Seal Security example — vulnerable Maven app (SnakeYAML CVE-2022-1471) remediated to sealed versions; GitHub Actions + Jenkins integration

Seal Security example — vulnerable pip app (PyYAML CVE-2020-14343) remediated to sealed versions; GitHub Actions + Jenkins integration

A self-hosted vulnerable Next.js environment running on Docker for simulating CVE-2025-55182. Built for educational security research and CTF…

CVE-2021-3007 Vulnerable Test Environment - Laminas/Zend Framework Deserialization RCE

AI-driven vulnerability discovery and live validation

Security training for the apps you actually ship. Open your browser and start hacking.

This repository contains a number of insecure self-hosted applications that allows interested security engineers to test vulnerabilities found by…

CRAReady SBOM test fixture — Java/Maven app with Log4Shell (CVE-2021-44228), Spring4Shell, Text4Shell, and other critical CVEs

Target Code + Exploit

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

Deploy a small, intentionally insecure, vulnerable Windows Domain for RDP Honeypot fully automatically.

WebApp intentionally made vulnerable to Race Condition for practicing Race Condition

A proof of concept exploit script for CVE-2025-55182


A deliberately Next.js app, vulnerable to CVE-2025-29927, Authorization Bypass

Multi-cloud vulnerable-by-design deployment tool using Terraform to provision intentionally insecure cloud infrastructure for security training and…

Self-contained Docker lab demonstrating CVE-2007-4559 (TarSlip) directory traversal via Python's tarfile module. Includes vulnerable and fixed APIs,…