Vulnerable Applications

Browse 16 vulnerable applications tools

Damn Vulnerable Web Services Logo

An intentionally vulnerable web application containing multiple web service security flaws designed for educational purposes and security testing practice.

1
WebGoat Logo

WebGoat is an OWASP-maintained deliberately insecure web application designed to teach web application security through hands-on exercises with intentional vulnerabilities.

0
Hackazon Logo

Hackazon is a vulnerable web application storefront designed for security professionals to practice testing modern web technologies and identifying common vulnerabilities.

0
MCIR Logo

MCIR is a unified framework for building code injection vulnerability testbeds that combines SQL, XML, shell, and XSS injection testing tools with shared functionality and template-based extensibility.

0
Java Vulnerable Logo

A deliberately vulnerable Java web application designed for educational purposes to teach web application security concepts and common vulnerabilities.

0
LAMPSecurity Training Logo

A series of vulnerable virtual machine images with documentation to teach Linux, Apache, PHP, MySQL security.

0
Commix-Testbed Logo

A collection of vulnerable web applications containing command injection flaws designed to test and evaluate detection and exploitation tools like commix.

0
Damn Vulnerable Web Application (DVWA) Logo

A deliberately vulnerable PHP/MySQL web application designed for security training, testing, and educational purposes in controlled environments.

0
damnvulnerable.me Logo

A deliberately vulnerable web application containing DOM-based XSS, CSRF, and other web vulnerabilities for security testing and educational purposes.

0
Penetration Testing Practice Lab - Vulnerable Apps/Systems Logo

Collection of URLs for vulnerable web applications and systems for cybersecurity practice.

0
DVWA - Brute Force (High Level) - Anti-CSRF Tokens Logo

A guide to brute forcing DVWA on the high security level with anti-CSRF tokens

0
0l4bs Cross-site scripting labs Logo

A collection of 20 cross-site scripting challenges covering various XSS attack vectors and filtering bypass techniques for educational purposes.

0
OWASP Damn Vulnerable Web Sockets (DVWS) Logo

A deliberately vulnerable web application that uses WebSocket communication to provide a training environment for learning about WebSocket-related security vulnerabilities.

0
Damn Small Vulnerable Web Logo

A deliberately vulnerable web application written in under 100 lines of Python code for educational purposes and web security testing.

0
WackoPicko Vulnerable Website Logo

WackoPicko is an intentionally vulnerable web application used for security testing, penetration testing practice, and vulnerability scanner evaluation.

0
OWASP Hackademic Challenges Logo

OWASP Hackademic Challenges is an educational web platform offering 10 realistic vulnerability scenarios for learning information security concepts through hands-on exploitation in a controlled environment.

0