Very Vulnerable Management API (VVMA) is a deliberately insecure RESTful API built with Node.js for educational and testing purposes. It includes vulnerabilities from the OWASP Top 10 API, allowing learners, security professionals, and developers to explore and understand common API security flaws.
☆71Jun 5, 2025Updated last year
Alternatives and similar repositories for VVMA
Users that are interested in VVMA are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Linux Space Booster is an advanced, secure disk space cleanup utility specifically designed for Linux virtual machines. It intelligently …☆15Jun 15, 2025Updated last year
- HuntersEye is designed for Bug Bounty Hunters, and Security Researchers to monitor new subdomains and certificates for specified domains.…☆21Dec 29, 2023Updated 2 years ago
- HackList: Your go-to AI-powered guide to hands-on cybersecurity learning!☆23Jul 6, 2025Updated last year
- A powerful Burp Suite extension that imports Postman collections☆32Aug 1, 2025Updated last year
- Zero trust. Zero security. Total exposure. A deliberately vulnerable health tech platform with AI Chatbot for learning about application …☆47Mar 27, 2026Updated 5 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Find credentials and secret with 170+ rules covering across source code, Web URL, and CI/CD, verifies them against vendor APIs, and gene…☆117Jul 3, 2026Updated 2 months ago
- A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities fou…☆101Nov 25, 2025Updated 9 months ago
- DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will auto…☆15Apr 2, 2026Updated 5 months ago
- A cross-platform desktop application for HTTP/HTTPS traffic interception and analysis, built with Go. Features modern UI, traffic manipul…☆225Apr 28, 2025Updated last year
- This is my personal repo, which includes bug bounty tips, a collection of tools, one-liners, and other resources I personally prefer whil…☆69Apr 25, 2025Updated last year
- CyberPreacher cloud project collection☆16Dec 21, 2025Updated 8 months ago
- Proxll is a tool designed to simplify the generation of proxy DLLs while addressing common conflicts related to windows.h☆41Oct 8, 2024Updated last year
- Learn how to intercept flutter apps☆25Jan 19, 2024Updated 2 years ago
- ☆100Apr 4, 2025Updated last year
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Penstaller: A Python tool to automate the installation of essential bug bounty and pentesting tools. With one command, it sets up tools f…☆19Mar 14, 2025Updated last year
- Azure AD (Entra ID) enumeration tool. Find related domains and tenant information in a simple way.☆37Oct 4, 2024Updated last year
- My notes containing the Certified Red Team Professional Course☆77Sep 7, 2024Updated 2 years ago
- CTF Helper is a powerful, modular Command Line Interface (CLI) tool designed for Capture The Flag (CTF) competitions and cybersecurity ta…☆35May 15, 2026Updated 3 months ago
- A modern tool written in python for hunting open redirection☆31Aug 8, 2023Updated 3 years ago
- A deliberately vulnerable banking application designed for practicing Security Testing of Web App, APIs, AI integrated App and secure cod…☆929Aug 5, 2026Updated last month
- You can gather useful information accounts by username across all types networks ( which also include social media)☆33Oct 19, 2023Updated 2 years ago
- My notes while studying for the PNPT from TCM Security.☆84Mar 30, 2024Updated 2 years ago
- ☆81Apr 28, 2025Updated last year
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- AprilTag is a visual fiducial system popular for robotics research.☆12Jun 23, 2024Updated 2 years ago
- Comprehensive AWS cloud reconnaissance and privilege escalation toolkit written in Python. Features IAM, EC2, S3, Lambda, ECS, Secrets Ma…☆50Jul 8, 2025Updated last year
- ☆11Sep 15, 2024Updated last year
- Modules designed to be used with the Conquest framework.☆22Updated this week
- Tools that can be useful for OSEP exam and PEN300 studies.☆99Mar 14, 2026Updated 5 months ago
- 🔍 erroreyes – Lightweight Subdomain Enumeration Tool A Python-based tool that queries crt.sh certificate logs to discover subdomains ass…☆17May 8, 2025Updated last year
- crack and generate jwt with ease☆24Mar 23, 2025Updated last year
- Research into Undocumented Behavior of Azure AD Refresh Tokens☆13Oct 27, 2023Updated 2 years ago
- ☆12Mar 8, 2025Updated last year
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- This is an advanced ASMI bypass that is currently undetected by Windows Defender and all the Antivirus software's on virustotal.☆27Jun 10, 2025Updated last year
- Collection of Notes and CheatSheets used for Red teaming Certs☆504Feb 13, 2023Updated 3 years ago
- free5GC official site☆15Updated this week
- MongoDB CVE-2025-14847 Heap Memory Leak Scanner | OP_COMPRESSED zlib Vulnerability | Bug Bounty & Red Team Tool☆35Dec 28, 2025Updated 8 months ago
- Patchless AMSI + ETW bypass via PAGE_GUARD exceptions and Vectored Exception Handler (VEH)☆16Mar 24, 2026Updated 5 months ago
- Defcon 28 - Red Team Village - Applied Purple Teaming - Why Can't We Be Friends☆26Aug 9, 2020Updated 6 years ago
- ☆12Dec 6, 2024Updated last year