Skip to content
Change the repository type filter

All

    Repositories list

    • A vulnerable Serverless application deployed on GCF
      JavaScript
      25001Updated Jan 1, 2026Jan 1, 2026
    • vulnerable OAuth 2.0 applications: understand the security implications of your OAuth 2.0 decisions.
      JavaScript
      78005Updated Jan 1, 2026Jan 1, 2026
    • Goatlin

      Public
      (aka Kotlin Goat) - an intentionally vulnerable Kotlin application
      Kotlin
      170002Updated Jan 1, 2026Jan 1, 2026
    • Damn Vulnerable Bank is designed to be an intentionally vulnerable android application. This provides an interface to assess your android application security hacking skills.
      Java
      223009Updated Dec 31, 2025Dec 31, 2025
    • JavaScript
      439005Updated Dec 31, 2025Dec 31, 2025
    • Java web common vulnerabilities and security code which is base on springboot and spring security
      Java
      760005Updated Dec 20, 2025Dec 20, 2025
    • dvja

      Public
      Damn Vulnerable Java (EE) Application
      CSS
      524002Updated Dec 19, 2025Dec 19, 2025
    • Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
      HTML
      934009Updated Dec 12, 2025Dec 12, 2025
    • Vulnerable app with examples showing how to not use secrets
      Java
      5130015Updated Dec 6, 2025Dec 6, 2025
    • "Vulnerable by Design" supply chain is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.
      HCL
      2780013Updated Dec 5, 2025Dec 5, 2025
    • Damn Vulnerable GraphQL Application is an intentionally vulnerable implementation of Facebook's GraphQL technology, to learn and practice GraphQL Security.
      JavaScript
      350005Updated Dec 5, 2025Dec 5, 2025
    • A free and open vulnerabilities database and the packages they impact. And the tools to aggregate and correlate these vulnerabilities. Sponsored by NLnet https://nlnet.nl/project/vulnerabilitydatabase/ for https://www.aboutcode.org/ Chat at https://gitter.im/aboutcode-org/vulnerablecode Docs at https://vulnerablecode.readthedocs.org/
      Python
      261005Updated Dec 5, 2025Dec 5, 2025
    • This is a project we created that has dependencies with vulnerabilities, for us to test out nancy
      Shell
      127003Updated Dec 5, 2025Dec 5, 2025
    • flask-webgoat is a deliberately-vulnerable application written with the Flask web framework.
      Python
      72002Updated Dec 2, 2025Dec 2, 2025
    • An scheduler to sync all forked repositories daily
      0101Updated Nov 21, 2025Nov 21, 2025
    • vulndb

      Public
      [mirror] The Go Vulnerability Database
      Go
      73003Updated Nov 20, 2025Nov 20, 2025
    • NodeGoat

      Public
      The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effectively address them.
      HTML
      2.2k004Updated Nov 18, 2025Nov 18, 2025
    • zipdu

      Public
      zipdu is a webservice implementation vulnerable to zip bombs and directory traversals. Written in multiple different languages
      C++
      3002Updated Nov 18, 2025Nov 18, 2025
    • SourceClear’s example node project with vulnerable methods in third party libraries
      JavaScript
      41002Updated Nov 16, 2025Nov 16, 2025
    • Solidity
      1.4k004Updated Aug 22, 2025Aug 22, 2025
    • r0uei

      Public
      A bad application, a vulnerable application to try SQLi 😈
      Ruby
      8001Updated May 8, 2025May 8, 2025
    • pygoat

      Public
      intentionally vuln web Application Security in django
      HTML
      1.2k005Updated May 8, 2025May 8, 2025
    • php-goof

      Public
      Snyk PHP Goof - A vulnerable PHP demo application
      PHP
      204001Updated May 6, 2025May 6, 2025
    • terragoat

      Public
      TerraGoat is Bridgecrew's "Vulnerable by Design" Terraform repository. TerraGoat is a learning and training project that demonstrates how common configuration errors can find their way into production cloud environments.
      HCL
      5.6k002Updated Apr 29, 2025Apr 29, 2025
    • AWSGoat

      Public
      AWSGoat : A Damn Vulnerable AWS Infrastructure
      PHP
      1.4k006Updated Apr 29, 2025Apr 29, 2025
    • An app with really insecure crypto. To be used to see/test/exploit weak cryptographic implementations as well as to learn a little bit more about crypto, without the need to dive deep into the math behind it
      TypeScript
      23003Updated Apr 29, 2025Apr 29, 2025
    • DVSA

      Public
      a Damn Vulnerable Serverless Application
      JavaScript
      199003Updated Apr 24, 2025Apr 24, 2025
    • vulhub

      Public
      Pre-Built Vulnerable Environments Based on Docker-Compose
      Dockerfile
      4.7k0017Updated Apr 24, 2025Apr 24, 2025
    • Intentionally vulnerable Go web app.
      Go
      53002Updated Apr 16, 2025Apr 16, 2025
    • OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
      TypeScript
      16k103Updated Mar 22, 2025Mar 22, 2025