vulnerable-application

There are 48 repositories under vulnerable-application topic.

  • vapi

    roottusk/vapi

    vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.

    Language:HTML1.2k1927311
  • oversecured/ovaa

    Oversecured Vulnerable Android App

    Language:Java66464178
  • rewanthtammana/Damn-Vulnerable-Bank

    Damn Vulnerable Bank is designed to be an intentionally vulnerable android application. This provides an interface to assess your android application security hacking skills.

    Language:Java6571910186
  • SasanLabs/VulnerableApp

    OWASP VulnerableApp Project: For Security Enthusiasts by Security Enthusiasts.

    Language:Java30110180420
  • logicalhacking/DVHMA

    Damn Vulnerable Hybrid Mobile App (DVHMA) is an hybrid mobile app (for Android) that intentionally contains vulnerabilities.

    Language:JavaScript25814157
  • oversecured/OversecuredVulnerableiOSApp

    Oversecured Vulnerable iOS App

    Language:Swift2168146
  • incredibleindishell/sqlite-lab

    This code is vulnerable to SQL Injection and having SQLite database. For SQLite database, SQL Injection payloads are different so it is for fun. Just enjoy it \m/

    Language:PHP16016032
  • HTBridge/pivaa

    Created by High-Tech Bridge, the Purposefully Insecure and Vulnerable Android Application (PIVAA) replaces outdated DIVA for benchmark of mobile vulnerability scanners.

    Language:Java1065264
  • vucsa

    Warxim/vucsa

    Vulnerable Client-Server Application (VuCSA) is made for learning how to perform penetration tests of non-http thick clients. It is written in Java (with JavaFX graphical user interface) and contains multiple challenges including SQL injection, RCE, XML vulnerabilities and more.

    Language:Java967128
  • JOSHUAJEBARAJ/GCP-GOAT

    GCP GOAT is the vulnerable application for learn the GCP Security

    Language:TypeScript631125
  • Vuldroid

    jaiswalakshansh/Vuldroid

    Vuldroid is a Vulnerable Android Application made with security issues in order to demonstrate how they can occur in code

    Language:Java623117
  • SasanLabs/VulnerableApp-facade

    VulnerableApp-facade is probably most modern lightweight distributed farm of Vulnerable Applications built for handling wide range of vulnerabilities across tech stacks.

    Language:TypeScript4743950
  • VulnerableLightApp

    Aif4thah/VulnerableLightApp

    Vulnerable API for educational purposes

    Language:C#322041
  • arall/vulnerabilities

    Examples of different vulnerabilities, in a variety of languages, shapes and sizes.

    Language:HTML272016
  • SVelizDonoso/wingkalabs

    Wingkalabs (Linux) Wingkalabs es una máquina Virtual Linux intencionalmente vulnerable. Esta máquina virtual se puede utilizar para realizar entrenamientos de seguridad, probar herramientas de seguridad y practicar técnicas comunes de pruebas de penetración.

  • codingo/cracknet

    A .net Crackme Challenge made for the SecTalks Brisbane 2017 Capture the Flag Event. Writeup/solution included.

    Language:C#2010012
  • sec4you/VulnLabs

    docker-compose bringing up multiple vulnerable applications inside containers.

  • OWASP/www-project-vulnerable-flask-app

    OWASP Foundation Web Respository

    Language:HTML148110
  • qwqoro/Mail-Injection

    📧 [Research] E-Mail Injection: Vulnerable applications

    Language:HTML14201
  • appsecco/owasp-webgoat-dot-net-docker

    Docker container for running OWASP WebGoat.NET application

  • vfapi

    naryal2580/vfapi

    Vulnerable FastAPI in reference to Opensource Web Application Security Project (OWASP) TOP 10: 2021

    Language:Python91011
  • lobuhi/lobuhi.github.io

    Rebujito is a fork of IppSec.Rocks and serves as a repo for hacking tools and other resources such as vulnerable apps, cheatsheets or methodologies.

    Language:JavaScript8001
  • UsagiB4/Vulnerable-Machines-for-Pentesting-and-Hacking

    This is a collection of vulnerable machines that can help you to learn hacking, pentesting and bug hunting. I know there are a lot of lists out there, but most of them are not updated regularly. So I decided to make on myself. Hope this will help you

  • vvmlist.github.io

    vvmlist/vvmlist.github.io

    vvmlist is a list of vulnerable vms with key techniques used on them to solve.

    Language:SCSS8213
  • m3ssap0/wordpress-really-simple-security-authn-bypass-vulnerable-application

    WARNING: This is a vulnerable application to test the exploit for the Really Simple Security < 9.1.2 authentication bypass (CVE-2024-10924). Run it at your own risk!

    Language:Dockerfile7100
  • videvelopers/Vulnerable-Flask-App

    This is a vulnerable Flask web application designed to provide a lab environment for people who want to improve their web penetration testing skills. It includes multiple types of vulnerabilities for you to practice exploiting.

    Language:Python70013
  • michealkeines/Vulnerable-API

    The Vulnerable API Python Application is a purposely flawed Python app that uses Flask, Jinja, and SQLite3. It contains intentional security vulnerabilities like XSS, SQLi, HHI, LFI, RFI, and SSTI. The project aims to serve as an educational tool to learn about and test automated API scanners. Use responsibly in controlled environments only.

    Language:Python6108
  • yusufarbc/DockerVuln

    A TUI enviorment for vulnerable app containers.

    Language:Shell4102
  • logicalhacking/DVGM

    Vulnerable Grade Management System

    Language:Ruby3308
  • mleblebici/Vulnerable-Cassandra-App

    testcases developed for research

    Language:HTML3100
  • th3r4ven/XSS-WEB-APP

    Language:Python3103
  • anir0y/vwa_docker

    vulnerable web application

    Language:PHP2202
  • irvinlim/vulnerability-testbeds

    Bootstrap various intentionally vulnerable web apps with Docker Compose

  • m3ssap0/wordpress-jetpack-broken-access-control-vulnerable-application

    WARNING: This is a vulnerable application to test the exploit for the Jetpack < 13.9.1 broken access control (CVE-2024-9926). Run it at your own risk!

    Language:Dockerfile2100
  • sec-zone/vuln_app

    Another vulnerable application for practicing web penetration testing.

    Language:Python2104
  • dr34mhacks/operation-file-hunt

    A vulnerable lab for understanding difference between LFI and File Retrieval

    Language:PHP1101