XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security.
☆1,762Sep 12, 2020Updated 5 years ago
Alternatives and similar repositories for xvwa
Users that are interested in xvwa are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Damn Vulnerable Web Services is an insecure web application with multiple vulnerable web service components that can be used to learn rea…☆460Dec 6, 2021Updated 4 years ago
- Vulnerable web site. Used to test sentinel features.☆11Nov 18, 2016Updated 9 years ago
- Damn Small Vulnerable Web☆875Dec 21, 2025Updated 7 months ago
- A modern vulnerable web app☆1,037Mar 11, 2021Updated 5 years ago
- A Ruby framework designed to aid in the penetration testing of WordPress systems.☆1,048Nov 24, 2019Updated 6 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- A collection of PHP backdoors. For educational or testing purposes only.☆2,269Mar 9, 2024Updated 2 years ago
- Server-Side Template Injection and Code Injection Detection and Exploitation Tool☆4,190Apr 21, 2024Updated 2 years ago
- Automated All-in-One OS Command Injection Exploitation Tool☆5,793Updated this week
- Welcome to the XSS Challenge Wiki!☆1,593Jun 24, 2020Updated 6 years ago
- The Magical Code Injection Rainbow! MCIR is a framework for building configurable vulnerability testbeds. MCIR is also a collection of co…☆447Aug 7, 2020Updated 5 years ago
- Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.☆8,965Nov 10, 2023Updated 2 years ago
- Git All the Payloads! A collection of web attack payloads.☆3,966May 15, 2023Updated 3 years ago
- OWSAP Damn Vulnerable Web Sockets (DVWS) is a vulnerable web application which works on web sockets for client-server communication.☆361Updated this week
- A DNS meta-query spider that enumerates DNS records, and subdomains.☆3,525Jan 13, 2022Updated 4 years ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- An automated script that download potential exploit for linux kernel from exploitdb, and compile them automatically☆497Sep 21, 2021Updated 4 years ago
- SSRF (Server Side Request Forgery) testing resources☆2,508Oct 12, 2024Updated last year
- A Tool for Domain Flyovers☆5,958May 22, 2022Updated 4 years ago
- Recon, Subdomain Bruting, Zone Transfers☆230Aug 2, 2016Updated 9 years ago
- Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods.☆1,781Dec 1, 2024Updated last year
- Sleepy Puppy XSS Payload Management Framework☆1,044Jul 24, 2018Updated 8 years ago
- Lab set-up for learning SQL Injection Techniques☆101Dec 6, 2020Updated 5 years ago
- Damn Vulnerable Web Application (DVWA)☆13,433May 30, 2026Updated 2 months ago
- A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and…☆3,967Sep 27, 2021Updated 4 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- ☆2,326Jun 10, 2026Updated last month
- Add headers to all Burp requests to bypass some WAF products☆329Jan 28, 2018Updated 8 years ago
- A curated list of resources for learning about application security☆7,007Feb 22, 2025Updated last year
- TCP/UDP Non-HTTP Proxy Extension (NoPE) for Burp Suite.☆1,662May 25, 2024Updated 2 years ago
- Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ …☆10,662Jul 4, 2026Updated 3 weeks ago
- The Bug Hunters Methodology☆4,382Aug 1, 2023Updated 2 years ago
- A ruby script that scans for vulnerable & exploitable 3rd-party web applications on a network☆575Dec 9, 2017Updated 8 years ago
- Empire is a PowerShell and Python post-exploitation agent.☆7,865Jan 19, 2020Updated 6 years ago
- Post Exploitation Collection☆1,584May 1, 2020Updated 6 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- This tool compares a targets patch levels against the Microsoft vulnerability database in order to detect potential missing patches on th…☆4,230May 11, 2023Updated 3 years ago
- A list of public penetration test reports published by several consulting firms and academic security groups.☆9,659Jun 7, 2026Updated last month
- EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.☆5,802Jan 5, 2026Updated 6 months ago
- Weaponized web shell☆3,534Oct 1, 2025Updated 9 months ago
- A collection of post-exploitation tools for network red teaming.☆139Dec 7, 2018Updated 7 years ago
- JexBoss: Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool☆2,520Jan 21, 2020Updated 6 years ago
- SQLI labs to test error based, Blind boolean based, Time based.☆5,812Dec 11, 2023Updated 2 years ago