Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
-
Updated
Apr 16, 2026 - HTML
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
Best hands-on lab for learning the fundamentals of cybersecurity and penetration testing workflows also packaged as Docker containers for fast, safe setup.
Sample vulnerable code and its exploit code
Dockerized PHP lab with XSS (cross-site scripting) challenges and filter-bypass examples for practising web exploitation.
Vulnerable Client-Server Application (VuCSA) is made for learning how to perform penetration tests of non-http thick clients. It is written in Java (with JavaFX graphical user interface) and contains multiple challenges including SQL injection, RCE, XML vulnerabilities and more.
VyAPI - A cloud based vulnerable hybrid Android App
Conviso Vulnerable Web Application is the OSS project from the Conviso Application Security for the community. The project represents a vulnerable web application to practice security testing and improve your learning in AppSec..
Dockerized PHP lab with file upload vulnerability challenges: bypass upload filters to achieve remote code execution.
gRPC Goat is a "Vulnerable by Design" lab created to provide an interactive, hands-on playground for learning and practicing gRPC security.
An intentionally vulnerable AI chatbot to learn and practice AI Security.
Web Application Pentesting Lab with over 40 plus vulnerability, which covers all the owasp top 10 issues.
Examples of different vulnerabilities, in a variety of languages, shapes and sizes.
See why a web vulnerability works, not just how to trigger it — a single-file, zero-dependency security lab that renders a vulnerable app as a 7-layer cross-section. 17 labs, attacker & defender modes, AI-authorable.
📧 [Research] E-Mail Injection: Vulnerable applications
OWASP Foundation Web Respository
LLMForge is probably the most modern AI vulnerability lab for OWASP VulnerableApp — real-LLM-backed labs for prompt injection, LLM-orchestrated BOLA, and RAG attacks.
Dockerized PHP lab: exploit a Local File Inclusion (LFI) vulnerability and escalate it to Remote Code Execution (RCE).
This is a collection of vulnerable machines that can help you to learn hacking, pentesting and bug hunting. I know there are a lot of lists out there, but most of them are not updated regularly. So I decided to make on myself. Hope this will help you
Deliberately vulnerable MCP server (aka MCP Goat) for security training — 26 challenges across 4 difficulty levels (incl. a secure reference), a victim-agent harness, and one-command Docker deploy. Practice penetration testing against the Model Context Protocol.
To associate your repository with the vulnerable-app topic, visit your repo's landing page and select "manage topics."