🌐 AI搜索 & 代理 主页
Skip to content
Change the repository type filter

All

    Repositories list

    • OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
      TypeScript
      16k1025Updated Dec 28, 2025Dec 28, 2025
    • javaspringvulny - a Spring Boot web application built wrong on purpose
      Java
      255200Updated Nov 4, 2025Nov 4, 2025
    • Damn Vulnerable MCP Server
      Python
      128107Updated Nov 3, 2025Nov 3, 2025
    • verademo

      Public
      A deliberately insecure Java web application
      Java
      5391014Updated Nov 1, 2025Nov 1, 2025
    • vuln_django_play

      Public
      🐛 An intentionally vulnerable Django app
      JavaScript
      34100Updated Jul 24, 2025Jul 24, 2025
    • WebGoat

      Public
      WebGoat is a deliberately insecure application
      JavaScript
      7.1k101Updated May 7, 2025May 7, 2025
    • 2000Updated Mar 18, 2025Mar 18, 2025
    • A vulnerable RESTful application written in Node and React based on OWASP API security top 10 2023 edition.
      JavaScript
      50002Updated Jan 17, 2025Jan 17, 2025
    • PaaS Cloud Goat is a simulated vulnerable Salesforce application providing hands-on experience with penetration testing of custom Salesforce applications.
      Apex
      5000Updated Nov 21, 2024Nov 21, 2024
    • NIVA is a simple web application which is intentionally vulnerable to NoSQL injection. The purpose of this project is to facilitate a better understanding of the NoSQL injection vulnerability among a wide audience of software engineers, security engineers, pentesters, and trainers.
      Java
      26001Updated Nov 12, 2024Nov 12, 2024
    • simple-ssrf

      Public
      Simple deliberately vulnerable API demonstrating Server-Side Request Forgery (SSRF).
      Python
      7004Updated Nov 9, 2024Nov 9, 2024
    • terragoat

      Public
      TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.
      HCL
      5.6k000Updated Nov 8, 2024Nov 8, 2024
    • This Lab contain the sample codes which are vulnerable to Server-Side Request Forgery attack
      PHP
      198000Updated Nov 8, 2024Nov 8, 2024
    • Collection of vulnerable APIs/apps to test JWT attacks
      JavaScript
      10508Updated Oct 31, 2024Oct 31, 2024
    • CVNA
      JavaScript
      23001Updated Oct 26, 2024Oct 26, 2024
    • PHP
      7002Updated Oct 20, 2024Oct 20, 2024
    • Mirror of broken crystals, but with specific dockerfiles for easy docker compose
      TypeScript
      5005Updated Oct 17, 2024Oct 17, 2024
    • A Broken Application - Very Vulnerable!
      TypeScript
      302000Updated Oct 16, 2024Oct 16, 2024
    • A very vulnerable implementation of a GraphQL API.
      TypeScript
      93002Updated Oct 11, 2024Oct 11, 2024
    • Python 3 compatible repo of Tiredful API
      Python
      10001Updated Oct 9, 2024Oct 9, 2024
    • Damn Vulnerable C# Application (API)
      C#
      282000Updated Sep 28, 2024Sep 28, 2024
    • An intentionally designed broken web application based on REST API.
      Python
      136000Updated Sep 27, 2024Sep 27, 2024
    • JavaScript
      368300Updated Sep 27, 2024Sep 27, 2024
    • OWASP VulnerableApp Project: For Security Enthusiasts by Security Enthusiasts.
      Java
      602005Updated Sep 27, 2024Sep 27, 2024
    • DVWA

      Public
      Damn Vulnerable Web Application (DVWA)
      PHP
      4.5k100Updated Sep 27, 2024Sep 27, 2024
    • Python
      1100Updated Sep 19, 2024Sep 19, 2024
    • HTML
      3000Updated Sep 19, 2024Sep 19, 2024
    • Vulnerable API for educational purposes
      C#
      78100Updated Sep 10, 2024Sep 10, 2024
    • The main goal of this repo is to learn about the gRPC communication patterns and hunt for vulnerabilities in the gRPC-Web app to improve your hunting skills
      JavaScript
      7002Updated Aug 31, 2024Aug 31, 2024
    • CSS
      5001Updated Aug 28, 2024Aug 28, 2024