OWASP Vulnerable Web Applications Directory (original) (raw)

Random App of the Day

App. URL Author Reference(s) Technology(ies) Note(s)
Damn Vulnerable File Upload - DVFU GitHub stars Thin Ba Shane (@art0flunam00n) GitHub contributors PHP GitHub last commit

VWAD

The OWASP Vulnerable Web Applications Directory (VWAD) Project is a comprehensive and well maintained registry of known vulnerable web and mobile applications currently available. These vulnerable web applications can be used by web developers, security auditors, and penetration testers to practice their knowledge and skills during training sessions (and especially afterwards), as well as to test at any time the multiple hacking tools and offensive techniques available, in preparation for their next real-world engagement.

The main goal of VWAD is to provide a list of vulnerable applications available to security professionals for hacking, offensive and defensive activities, so that they can manipulate realistic web environments… without going to jail :grinning:

The vulnerable web applications have been classified in four categories: Online, Offline, Mobile, and VMs/ISOs. Each list has been ordered alphabetically.

An initial list that inspired this project was maintained till October 2013 here.

A brief description of the OWASP VWAD project is available here.

Open Hub Stats


On-line Resources Used

Other Vulnerable Web-app Compilations


Mobile

App. URL Author Reference(s) Technology(ies) Note(s)
AndroGoat GitHub stars satishpatnayak GitHub contributors Download Kotlin Android GitHub last commit
Damn Vulnerable Bank GitHub stars Rewanth Tammana, Akshansh Jaiswal, Hrushikesh Kakade GitHub contributors Guide android GitHub last commit
Goatlin GitHub stars Checkmarx GitHub contributors Guide Kotlin Android API REST GitHub last commit
MSTG CrackMes GitHub stars OWASP GitHub contributors GitHub last commit
MSTG Hacking Playground GitHub stars OWASP GitHub contributors Guide GitHub last commit
Vuln-Bank Al-Amir Badmus Download Python JavaScript Postgres Docker HTML/CSS A deliberately vulnerable banking application designed for practicing secure code reviews and API security testing. Features common vulnerabilities found in real-world applications, making it an ideal platform for security professionals, developers, and enthusiasts to learn security testing and secure coding practices in a safe environment.

Offline

App. URL Author Reference(s) Technology(ies) Note(s)
.NET Goat GitHub stars OWASP GitHub contributors C# Original main repo: https://github.com/jerryhoff/WebGoat.NET. Others: https://github.com/rapPayne/WebGoat.Net , https://github.com/jowasp/WebGoat.NET. GitHub last commit
AI-Goat fhammon, Guanwei Hu Download Python Vicuna LLM LLaMa AI Goat uses the Vicuna LLM which derived from Meta's LLaMA and coupled with ChatGPT's response data. When installing AI Goat the LLM binary is downloaded from third party locally on your computer.
Altoro Mutual (AltoroJ) GitHub stars IBM/Watchfire GitHub contributors Download Live J2EE Log in with jsmith/demo1234 or admin/admin GitHub last commit
AuthLab GitHub stars digininja (Robin Wood) GitHub contributors Guide Live GO GitHub last commit
BodgeIt Store GitHub stars Simon Bennetts (psiinon) GitHub contributors Download Docker Java GitHub last commit
Bricks OWASP Download Guide PHP
Broken Crystals GitHub stars NeuraLegion GitHub contributors Live react Node Swagger GitHub last commit
Butterfly Security Project Download PHP Last updated in 2008
CVWA - Conviso Vulnerable Web Application GitHub stars Conviso AppSec GitHub contributors Download PHP GitHub last commit
CloudGoat GitHub stars Rhino Security Labs GitHub contributors Guide Announcement Docker Python AWS GitHub last commit
CryptOMG GitHub stars SpiderLabs GitHub contributors Download PHP GitHub last commit
Cyclone Transfers GitHub stars GitHub contributors Ruby on Rails GitHub last commit
DIWA - Deliberately Insecure Web Application GitHub stars Tim Steufmehl GitHub contributors Guide PHP Docker A Deliberately Insecure Web Application GitHub last commit
Damn Small Vulnerable Web (DSVW) GitHub stars Miroslav Stampar GitHub contributors Python GitHub last commit
Damn Vulnerable Application Scanner (DVAS) GitHub stars Andrea Valenza, Enrico Russo, Gabriele Costa GitHub contributors Guide Announcement PHP An intentionally vulnerable web application scanner GitHub last commit
Damn Vulnerable C# Application (API) GitHub stars Appsecco GitHub contributors Guide Docker C# dotnet GitHub last commit
Damn Vulnerable Electron App (DVEA) GitHub stars Najam Ul Saqib (cybersoldier) GitHub contributors Announcement Download ElectronJS A deliberately insecure ElectronJS application GitHub last commit
Damn Vulnerable File Upload - DVFU GitHub stars Thin Ba Shane (@art0flunam00n) GitHub contributors PHP GitHub last commit
Damn Vulnerable Functions as a Service (DVFaaS) GitHub stars we45 (Abhay Bhargav) GitHub contributors Guide Python AWS GitHub last commit
Damn Vulnerable GraphQL Application (DVGA) GitHub stars Dolev Farhi <[email protected]>, Connor McKinnon GitHub contributors Python HTML Javascript GraphQL SQLAlchemy docker GitHub last commit
Damn Vulnerable Node Application - DVNA GitHub stars Claudio Lacayo GitHub contributors Node.js GitHub last commit
Damn Vulnerable NodeJS Application - DVNA GitHub stars @appsecco GitHub contributors Node.js Different project from the old DVNA GitHub last commit
Damn Vulnerable OAuth 2.0 Applications GitHub stars Koen Buyens GitHub contributors MEAN Docker OAuth 2.0 A set of vulnerable applications which show Oauth2.0 vulnerabilities. GitHub last commit
Damn Vulnerable Python Web Application - DVPWA GitHub stars Oleksandr Kovalchuk GitHub contributors Python Docker GitHub last commit
Damn Vulnerable Restaurant GitHub stars theowni GitHub contributors Guide Python Docker Damn Vulnerable Restaurant is an intentionally vulnerable Web API game for learning and training purposes dedicated to developers, ethical hackers and security engineers. GitHub last commit
Damn Vulnerable Serverless App (DVSA) GitHub stars Protego Labs GitHub contributors Guide Node AWS Azure GitHub last commit
Damn Vulnerable Stateful WebApp GitHub stars dnet GitHub contributors Download PHP GitHub last commit
Damn Vulnerable Web Application - DVWA GitHub stars RandomStorm GitHub contributors Download Docker PHP GitHub last commit
Damn Vulnerable Web Services GitHub stars snoopysecurity GitHub contributors Web Services GitHub last commit
Damn Vulnerable Web Sockets GitHub stars @appsecco GitHub contributors Web Sockets GitHub last commit
DjangoGoat GitHub stars Red and Black GitHub contributors Python Django GitHub last commit
EasyBuggy GitHub stars Kohei Tamura GitHub contributors Download Guide Java GitHub last commit
Extreme Vulnerable Node Application GitHub stars vegabird GitHub contributors Download NodeJS GitHub last commit
FFUF.me GitHub stars adamtlangley GitHub contributors Download Live PHP Docker Target practice for ffuf GitHub last commit
Generic-University GitHub stars Katie Paxton-Fear GitHub contributors PHP docker API GraphQL MySQL Laravel GitHub last commit
Goof GitHub stars Snyk GitHub contributors Guide Guide NodeJS online - via Heroku deploy GitHub last commit
Gruyere Google Download Live Python
Hackademic Challenges Project GitHub stars OWASP GitHub contributors Download PHP Joomla GitHub last commit
Hackazon GitHub stars Rapid7 (NTObjectives) GitHub contributors Download Guide Guide Guide AJAX JSON XML GwT AMF GitHub last commit
Hackxor albinowax Download Guide Live VMware First 2 levels online, rest offline. Web application hacking game via missions, based on real vulnerabilities.
Hacme Bank McAfee / Foundstone Download .NET
Hacme Bank - Android McAfee / Foundstone
Hacme Books McAfee / Foundstone Download Java
Hacme Casino McAfee / Foundstone Download Ruby on Rails
Hacme Shipping McAfee / Foundstone Download ColdFusion
Hacme Travel McAfee / Foundstone Download C++
Hammer GitHub stars iknowjason GitHub contributors Download Live Ruby on Rails Includes manual build and docker options. GitHub last commit
LAMPSecurity Download VMware PHP
Magical Code Injection Rainbow - MCIR GitHub stars SpiderLabs GitHub contributors PHP GitHub last commit
Marathon GitHub stars Christian Schneider GitHub contributors JAVA Docker Vulnerable demo application GitHub last commit
Mutillidae GitHub stars GitHub contributors Download PHP GitHub last commit
NoSQL Injection Lab GitHub stars @digininja GitHub contributors Download PHP MongoDB GitHub last commit
NoSQL Injection Vulnerable App (NIVA) GitHub stars Anton Abashkin GitHub contributors Docker Guide Java MongoDB GitHub last commit
NodeGoat GitHub stars OWASP GitHub contributors Download Node.js GitHub last commit
NodeVulnerable GitHub stars cr0hn GitHub contributors Node.js GitHub last commit
OSTE-Vulnerable-Web-Application GitHub stars (OSTE)Oudjani seyyid taqi eddine GitHub contributors PHP Vulnerable web application GitHub last commit
OWASP Damn Vulnerable Web Sockets (DVWS) GitHub stars Abhineet Jayaraj (@xploresec) GitHub contributors Download PHP HTML Javascript WebSockets GitHub last commit
OWASP Juice Shop GitHub stars OWASP GitHub contributors Download Docker Guide Demo Preview Live TypeScript JavaScript Angular Node.js GitHub last commit
OWASP SKF Labs GitHub stars [email protected] and [email protected] GitHub contributors Demo Guide Live Python HTML Javascript GraphQL Ruby You can go to the demo website and login(admin / test-skf) or skip login, go to Labs menu and start a Lab you want to do. Please limit the usage of scanning tools on the Labs. GitHub last commit
OWASP VulnerableApp GitHub stars Karan Preet Singh Sasan GitHub contributors Docker Download Java Javascript Spring-Boot GitHub last commit
OWASP VulnerableApp-facade GitHub stars Karan Preet Singh Sasan GitHub contributors Docker Download Typescript Javascript Docker GitHub last commit
Peruggia Download PHP
Pixi GitHub stars OWASP GitHub contributors Download Download Guide Guide Node.js Swagger docker GitHub last commit
Puzzlemall Download Java
PyGoat GitHub stars Ade Yoseman GitHub contributors Guide Docker Download Live Python GitHub last commit
Race The Web GitHub stars insp3ctre GitHub contributors Download GitHub last commit
Rails Goat GitHub stars OWASP GitHub contributors Download Downloads Ruby on Rails GitHub last commit
SQL injection test environment GitHub stars GitHub contributors PHP SQLmap Project GitHub last commit
SQLI-labs GitHub stars GitHub contributors Download Guide PHP GitHub last commit
SQLol GitHub stars GitHub contributors Download PHP GitHub last commit
SSRF Vuln Lab GitHub stars incredibleindishell, Mohammed Farhan GitHub contributors Docker PHP GitHub last commit
SecDevLabs GitHub stars Globo GitHub contributors Guide Go NodeJS Python PHP React Angular/Spring Dart/Flutter Repository with many intentionally vulnerable web applications. Includes attack narratives and docker options for each app. GitHub last commit
Security Shepherd GitHub stars OWASP GitHub contributors Download Java GitHub last commit
TicketMagpie GitHub stars GitHub contributors Download Java GitHub last commit
Tiredful API GitHub stars @payatu GitHub contributors Download Python Django GitHub last commit
UnSAFE Bank GitHub stars lucideus GitHub contributors Docker Web, Android and iOS application GitHub last commit
Varnish HTTP/2 Request Smuggling GitHub stars Detectify GitHub contributors Announcement Varnish HTTP/2 A docker-compose file to setup a local environment that is vulnerable to CVE-2021-36740 Varnish HTTP/2 request smuggling, presented by Albinowax at Blackhat/Defcon 2021. GitHub last commit
Vuln-Bank Al-Amir Badmus Download Python JavaScript Postgres Docker HTML/CSS A deliberately vulnerable banking application designed for practicing secure code reviews and API security testing. Features common vulnerabilities found in real-world applications, making it an ideal platform for security professionals, developers, and enthusiasts to learn security testing and secure coding practices in a safe environment.
VulnLab GitHub stars Yavuzlar (siberyavuzlar.com) GitHub contributors PHP Docker A web vulnerability lab project developed by Yavuzlar. GitHub last commit
Vulnerable Java Web Application GitHub stars Cyber Security and Privacy Foundation GitHub contributors Java GitHub last commit
Vulnerable Node Express GitHub stars Zachary Conger GitHub contributors Node.js Express SQLi and XSS GitHub last commit
Vulnerable OTP App GitHub stars mddanish GitHub contributors PHP Google OTP GitHub last commit
Vulnerable SAML App GitHub stars yogisec GitHub contributors Python GitHub last commit
VulnerableLightApp GitHub stars Michael Vacarella GitHub contributors Guide .NET C# AspNetCore Vulnerable API for educational purposes GitHub last commit
VulnerableXsltConsoleApplication GitHub stars Context Information Security GitHub contributors .Net This is a console app, however it relates to an issues that is relevant to web apps: use of XSLT transforms for XML files. GitHub last commit
WAVSEP - Web Application Vulnerability Scanner Evaluation Project GitHub stars Shay Chen GitHub contributors Download Downloads Downloads Java GitHub last commit
WIVET- Web Input Vector Extractor Teaser Download Downloads
WackoPicko GitHub stars GitHub contributors Download PHP GitHub last commit
WebGoat GitHub stars OWASP GitHub contributors Download Guide Docker Java GitHub last commit
WebGoatPHP GitHub stars OWASP GitHub contributors Download Downloads PHP GitHub last commit
WrongSecrets GitHub stars Jeroen Willemsen (@commjoen), Ben de Haan (@bendehaan), Nanne Baars (@nbaars) GitHub contributors Download JavaScript Java Hashicorp Vault Kubernetes Docker AWS GCP OWASP WrongSecrets is a vulnerable app used to show how to not use secrets. GitHub last commit
XXE Lab GitHub stars Joshua Barone GitHub contributors docker vagrant GitHub last commit
Xtreme Vulnerable Web Application (XVWA) GitHub stars @s4n7h0, @samanL33T GitHub contributors Download PHP MySQL GitHub last commit
Yrprey Fernando Mengali, Vagner Mengali Download Download Docker PHP TypeScript NextJs Framework created in NextJs (TypeScript) and PHP/MySQL with OWASP TOP 10 API vulnerabilities of 2019 and 2023. Yrprey can was created for educational purposes, contributing to the teaching and learning of those interested in Pentest (intrusion testing) and Application Security (Appsec).
YrpreyBlog Fernando Mengali Download PHP CSS Bootstrap MySQL A framework created in PHP/MySQL with OWASP TOP 10 Web Application vulnerabilities.
YrpreyC Fernando Mengali Download C YrpreyC is a framework written in the C language that contains vulnerabilities related to memory issues, categorized as overflows
YrpreyC++ Fernando Mengali Download C++ YrpreyC++ is a framework written in the C++ language that contains vulnerabilities related to memory issues, categorized as overflows
YrpreyPHP Fernando Mengali Download PHP CSS Bootstrap MySQL A framework created in PHP/MySQL with OWASP TOP 10 Web Application vulnerabilities. YrpreyPHP was created for educational purposes, contributing to the teaching and learning of those interested in Pentest (intrusion testing) and Application Security (AppSec).
YrpreyPathTraversal Fernando Mengali Download PHP MySQL Semantic UI Bootstrap YrpreyPathTraversal is a framework written in PHP, with examples of exploiting Path Traversal and Local File Inclusion vulnerabilities in different ways.
Zero Health Aliyu G. Yisa Download Guide Demo React NodeJS JavaScript Postgres Docker Ollama Swagger/OpenAPI Zero trust. Zero security. Total exposure. A deliberately vulnerable health tech platform with AI Chatbot for learning about application security and ethical hacking. It contains vulnerabilities from OWASP top 10 Web, API and AI/LLM Security Vulnerabilities. Highly vulnerable, never use in production.
bWAPP Download Guide PHP
crAPI GitHub stars OWASP GitHub contributors Downloads Go nginx GitHub last commit
dvws-node GitHub stars @snoopysecurity GitHub contributors Guide Web Services NodeJS GitHub last commit
insecure-deserialisation-net-poc GitHub stars Omer Levi Hevroni GitHub contributors .NET JSON yoserial.NET A small webserver vulnerable to insecure deserialization GitHub last commit
jwtdemo GitHub stars Sjoerd Langkemper (Sjord) GitHub contributors Guide PHP Practice hacking JWT tokens. GitHub last commit
play-webgoat GitHub stars GitHub contributors Java Scala Play Framework GitHub last commit
twitterlike GitHub stars Sakti Dwi Cahyono GitHub contributors Download PHP GitHub last commit
vAPI GitHub stars Tushar Kulkarni GitHub contributors Guide Docker PHP vAPI is a Vulnerable Interface that demonstrates the OWASP API Top 10 vulnerabilities in the means of exercises GitHub last commit
vuln-node.js-express.js-app GitHub stars SirAppSec GitHub contributors Download Docker Node.js Express.js swagger sqlite sequelize A Very Vulnerable Node.js Express.js Web Application and API. Used for testing Security tools, Application security and penetration testing. Using Swagger, Sqlite, Sequelize. GitHub last commit
vulnerable-api GitHub stars Matthew Valdes GitHub contributors Download Python GitHub last commit
websheep GitHub stars Younes Jaaidi (yjaaidi) GitHub contributors Guide Angular JavaScript Node Websheep is an app based on a willingly vulnerable ReSTful APIs. GitHub last commit
ypreyAPINodeJS Fernando Mengali Download NodeJS PHP MariaDB Bootstrap JavaScript yrpreyAPINodeJS is a vulnerable framework written in NodeJS and based on the OWASP TOP 10 API.
ypreyAPIPython Fernando Mengali Download Python PHP MariaDB Bootstrap JavaScript ypreyAPIPython is a vulnerable framework written in Python and based on the OWASP TOP 10 API.
ypreyPollsPHP Fernando Mengali Download PHP MySQL Materialize Bootstrap ypreyPollsPHP is a vulnerable framework written in PHP with a polls management scenario, based on the OWASP TOP 10
yrpreyASPC Fernando Mengali Download ASP MySQL C yrpreyASPC is a vulnerable framework written in ASP and C with vulnerabilities based on Buffer Overflow, Command Injection, and web application vulnerabilities.
yrpreyASPCPlus Fernando Mengali Download ASP MySQL C++ yrpreyASPCPlus is a vulnerable framework written in ASP and C++ with vulnerabilities based on Buffer Overflow, Command Injection, and web application vulnerabilities.
yrpreyFinance Fernando Mengali Download PHP MySQL Bootstrap yrpreyFinance is a vulnerable framework written in PHP with a financial management scenario, based on the OWASP TOP 10
yrpreyLibrary Fernando Mengali Download PHP MySQL Bootstrap yrpreyLibrary is a vulnerable framework written in PHP, based on the OWASP TOP 10
yrpreyPollsNodeJS Fernando Mengali Download NodeJS PHP MySQL Materialize Bootstrap yrpreyPollsNodeJS is a vulnerable framework written in NodeJS with a polls management scenario, based on the OWASP TOP 10
yrpreyPollsPerl Fernando Mengali Download Perl PHP MySQL Materialize Bootstrap yrpreyPollsPerl is a vulnerable framework written in Perl with a polls management scenario, based on the OWASP TOP 10
yrpreyPollsPython Fernando Mengali Download Python PHP MySQL Materialize Bootstrap yrpreyPollsPython is a vulnerable framework written in Python with a polls management scenario, based on the OWASP TOP 10
yrpreyTasks Fernando Mengali Download PHP MySQL Bootstrap yrpreyTasks is a vulnerable framework written in PHP with a task management scenario, based on the OWASP TOP 10
yrpreyTasksNodeJS Fernando Mengali Download NodeJS PHP MySQL Bootstrap yrpreyTasksNodeJS is a vulnerable framework written in NodeJS with a task management scenario, based on the OWASP TOP 10
yrpreyTasksPython Fernando Mengali Download Python PHP MySQL Bootstrap yrpreyTasksPython is a vulnerable framework written in Python with a task management scenario, based on the OWASP TOP 10

Online

App. URL Author Reference(s) Technology(ies) Note(s)
Acuart Acunetix Live PHP Art shopping
Altoro Mutual (AltoroJ) GitHub stars IBM/Watchfire GitHub contributors Download Live J2EE Log in with jsmith/demo1234 or admin/admin GitHub last commit
AuthLab GitHub stars digininja (Robin Wood) GitHub contributors Guide Live GO GitHub last commit
BGA Vulnerable BANK App BGA Security Live .NET
Broken Crystals GitHub stars NeuraLegion GitHub contributors Live react Node Swagger GitHub last commit
BugBait - Vulnerable Web Application Blacklock Security Live Node.js bugbait.io is a vulnerable web application for students, developers, cyber enthusiasts and pen testers to identify and exploit the vulnerabilities.
CTFLearn @ctflearn Live
Cyber Scavenger Hunt GitHub stars Arthur Kay GitHub contributors Download Live Javacript React A simple scavenger hunt to learn about pentesting a website or web application. GitHub last commit
Defend the Web Luke [flabbyrabbit] Live Formerly HackThis
FFUF.me GitHub stars adamtlangley GitHub contributors Download Live PHP Docker Target practice for ffuf GitHub last commit
Firing Range GitHub stars Google GitHub contributors Download Live GitHub last commit
Game of Hacks Checkmarx Live Node Express.js
Gin & Juice Shop PortSwigger Announcement Live JavaScript AngularJS React CSRF A hosted always-online demo app with realistic technologies.
Gruyere Google Download Live Python
Hack.me eLearnSecurity Beta
HackThis GitHub stars Luke Ward (0x6C77) GitHub contributors Download Live PHP GitHub last commit
HackThisSite HackThisSite Staff Live PHP Perl JavaScript API Binaries Always-on CTF challenges including Basic, Realistic, Application, Steganography, and many others.
HackXpert theXSSrat Guide Live PHP
HackYourselfFirst Troy Hunt Guide Live
Hacking Lab Hacking Lab Live
Hackxor albinowax Download Guide Live VMware First 2 levels online, rest offline. Web application hacking game via missions, based on real vulnerabilities.
Netsparker Test App .NET Netsparker Live ASP.NET
Netsparker Test App PHP Netsparker Live PHP
OWASP Juice Shop GitHub stars OWASP GitHub contributors Download Docker Guide Demo Preview Live TypeScript JavaScript Angular Node.js GitHub last commit
OWASP SKF Labs GitHub stars [email protected] and [email protected] GitHub contributors Demo Guide Live Python HTML Javascript GraphQL Ruby You can go to the demo website and login(admin / test-skf) or skip login, go to Labs menu and start a Lab you want to do. Please limit the usage of scanning tools on the Labs. GitHub last commit
Pentest-Ground Pentest-Tools.com PHP Docker Suite of vulnerable web apps to practice
Pentester Academy Live
PyGoat GitHub stars Ade Yoseman GitHub contributors Guide Docker Download Live Python GitHub last commit
Security Tweets Acunetix Live HTML5
Solyd - Introdução ao Hacking e Pentest Solyd PHP Linux In Portuguese (Português) - Free online trainning with free online lab
Zero Bank Micro Focus Fortify (was HP/SpiDynamics) Live (username/password)

VM-ISO

App. URL Author Reference(s) Technology(ies) Note(s)
Bee-Box VMware
BodgeIt Store GitHub stars Simon Bennetts (psiinon) GitHub contributors Download Docker Java GitHub last commit
Broken Web Applications Project (BWA) - OWASP OWASP - Chuck Willis Download Download VMware
CI/CD Goat GitHub stars Cider GitHub contributors Gitea Jenkins GitLab Docker Deliberately vulnerable CI/CD environment. Hack CI/CD pipelines, capture the flags. GitHub last commit
CloudGoat GitHub stars Rhino Security Labs GitHub contributors Guide Announcement Docker Python AWS GitHub last commit
DIWA - Deliberately Insecure Web Application GitHub stars Tim Steufmehl GitHub contributors Guide PHP Docker A Deliberately Insecure Web Application GitHub last commit
Damn Vulnerable C# Application (API) GitHub stars Appsecco GitHub contributors Guide Docker C# dotnet GitHub last commit
Damn Vulnerable GraphQL Application (DVGA) GitHub stars Dolev Farhi <[email protected]>, Connor McKinnon GitHub contributors Python HTML Javascript GraphQL SQLAlchemy docker GitHub last commit
Damn Vulnerable Web Application - DVWA GitHub stars RandomStorm GitHub contributors Download Docker PHP GitHub last commit
Exploit.co.il Vuln Web App Download VMware
FFUF.me GitHub stars adamtlangley GitHub contributors Download Live PHP Docker Target practice for ffuf GitHub last commit
Game of Active Directory GitHub stars Orange-Cyberdefense GitHub contributors Guide Windows Active Directory Requires a considerably powerful system GitHub last commit
GameOver Download VMware
Generic-University GitHub stars Katie Paxton-Fear GitHub contributors PHP docker API GraphQL MySQL Laravel GitHub last commit
Goof GitHub stars Snyk GitHub contributors Guide Guide NodeJS online - via Heroku deploy GitHub last commit
Hackxor albinowax Download Guide Live VMware First 2 levels online, rest offline. Web application hacking game via missions, based on real vulnerabilities.
LAMPSecurity Download VMware PHP
Log4Shell sample vulnerable application GitHub stars Christophe Tafani-Dereeper, Gerard Arall, rayhan0x01 Rayhan Ahmed GitHub contributors Spring Boot Log4j Java CVE-2021-44228 GitHub last commit
Metasploitable 2 Download VMware
Metasploitable 3 GitHub stars GitHub contributors Download VMware GitHub last commit
Moth Download VMware
NoSQL Injection Vulnerable App (NIVA) GitHub stars Anton Abashkin GitHub contributors Docker Guide Java MongoDB GitHub last commit
OWASP Juice Shop GitHub stars OWASP GitHub contributors Download Docker Guide Demo Preview Live TypeScript JavaScript Angular Node.js GitHub last commit
PentesterLab - The Exercises ISO PDF
Pixi GitHub stars OWASP GitHub contributors Download Download Guide Guide Node.js Swagger docker GitHub last commit
PyGoat GitHub stars Ade Yoseman GitHub contributors Guide Docker Download Live Python GitHub last commit
Samurai WTF Download ISO
Sauron Download Quemu
Security Labs & POCs GitHub stars DataDog GitHub contributors docker Kubernetes PiPy OpenSSL JWT GitHub last commit
Template Injection Playground GitHub stars Hackmanit and Maximilian Hildebrand GitHub contributors Docker Various Template Engines GitHub last commit
VAmPI GitHub stars erev0s GitHub contributors Guide Announcement python docker OpenAPI GitHub last commit
Virtual Hacking Lab Download ZIP
Vuln-Bank Al-Amir Badmus Download Python JavaScript Postgres Docker HTML/CSS A deliberately vulnerable banking application designed for practicing secure code reviews and API security testing. Features common vulnerabilities found in real-world applications, making it an ideal platform for security professionals, developers, and enthusiasts to learn security testing and secure coding practices in a safe environment.
Vulnado GitHub stars ScaleSec GitHub contributors Java Docker Purposely vulnerable Java application to help lead secure coding workshops GitHub last commit
Wayfarer GitHub stars SamuraiWTF GitHub contributors Docker OAuth React GitHub last commit
Web Security Dojo Download VMware VirtualBox
XXE Download VMware
XXE Lab GitHub stars Joshua Barone GitHub contributors docker vagrant GitHub last commit
Zero Health Aliyu G. Yisa Download Guide Demo React NodeJS JavaScript Postgres Docker Ollama Swagger/OpenAPI Zero trust. Zero security. Total exposure. A deliberately vulnerable health tech platform with AI Chatbot for learning about application security and ethical hacking. It contains vulnerabilities from OWASP top 10 Web, API and AI/LLM Security Vulnerabilities. Highly vulnerable, never use in production.
crAPI GitHub stars OWASP GitHub contributors Downloads Go nginx GitHub last commit
c{api}tal GitHub stars Checkmarx GitHub contributors Docker postgres OpenAPI Python GitHub last commit
dvws-node GitHub stars @snoopysecurity GitHub contributors Guide Web Services NodeJS GitHub last commit
vuln-node.js-express.js-app GitHub stars SirAppSec GitHub contributors Download Docker Node.js Express.js swagger sqlite sequelize A Very Vulnerable Node.js Express.js Web Application and API. Used for testing Security tools, Application security and penetration testing. Using Swagger, Sqlite, Sequelize. GitHub last commit