An intentionally vulnerable Spring Boot application designed for security research, defensive analysis, and secure coding education in modern Java-based systems.
-
Updated
Feb 4, 2026 - Java
An intentionally vulnerable Spring Boot application designed for security research, defensive analysis, and secure coding education in modern Java-based systems.
A curated list of VULNERABLE APPS and SYSTEMS which can be used as PENETRATION TESTING PRACTICE LAB.
Bash script to manage insecure web apps using docker and hosts aliases for pentest practice
Deliberately vulnerable REST API for OWASP Top 10 (2023) security testing and learning.
gRPC Goat is a "Vulnerable by Design" lab created to provide an interactive, hands-on playground for learning and practicing gRPC security.
Capture the flag challenges
A very silly vulnerable application to review your knowledge about basics of cybersecurity.
Sample Java source code containing vulnerabilities to illustrate Fortify usage
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
An insecure React Native mobile application for use in Micro Focus demonstrations
Damn Vulnerable NodeJS Application
Repository for code, PoCs and others for "Security development for Muggles"
Add a description, image, and links to the vulnerable-apps topic page so that developers can more easily learn about it.
To associate your repository with the vulnerable-apps topic, visit your repo's landing page and select "manage topics."