A curated list of VULNERABLE APPS and SYSTEMS which can be used as PENETRATION TESTING PRACTICE LAB.
☆55Mar 29, 2023Updated 3 years ago
Alternatives and similar repositories for awesome-vulnerable
Users that are interested in awesome-vulnerable are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆15Jul 17, 2024Updated 2 years ago
- ☆14Feb 4, 2020Updated 6 years ago
- A security-first linter for code that shouldn't need linting☆19Sep 12, 2023Updated 2 years ago
- penetration testing scripts and Information share☆11Dec 15, 2024Updated last year
- A fast, customizable service detection tool powered by a flexible fingerprint system. It helps you identify services, APIs, and network c…☆47Jun 23, 2026Updated 3 weeks ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Protect against subdomain takeover☆94Updated this week
- Screenshot Shenanigans☆25Nov 20, 2017Updated 8 years ago
- Small wiki for Mobile Application Penetration Testing Tools☆12Apr 8, 2021Updated 5 years ago
- LC256 - CBM style 256 color SMD computer☆18Jun 15, 2025Updated last year
- Additional active scan checks for BURP☆28Oct 3, 2024Updated last year
- Offensive Assembly code snippets.☆13Jul 12, 2023Updated 3 years ago
- HashiCorp-relevant rules for the Semgrep code analysis tool☆42Oct 3, 2023Updated 2 years ago
- The aim of the project is to develop intentionally vulnerable source code in various languages.☆16Mar 3, 2026Updated 4 months ago
- Decoupled AI copilot for pentesting & CTFs. Sidecar tails your shell history, parses tool outputs, grounds suggestions in your notes, and…☆13Updated this week
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- ☆116Feb 11, 2026Updated 5 months ago
- Very loud vBulletin exploit☆14Aug 12, 2020Updated 5 years ago
- Create tar/zip archives that try to exploit zipslip vulnerability.☆48Sep 20, 2024Updated last year
- A set of scripts to install a Burp Collaborator Server in a docker environment, using a LetsEncrypt wildcard certificate in as simple a p…☆31Nov 30, 2025Updated 7 months ago
- ☆10Mar 25, 2025Updated last year
- RenameLocalVars is an IDA plugin that renames local variables to something easier to read.☆15Jul 9, 2023Updated 3 years ago
- Validate native AWS security services are properly configured across your AWS Organization☆77May 22, 2026Updated last month
- littleoldearthquake☆12Jul 15, 2014Updated 12 years ago
- Automated web vulnerability scanning with LLM agents☆478Jun 18, 2025Updated last year
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- ☆31Oct 28, 2024Updated last year
- A little Kata to practice clean code☆16Jul 9, 2017Updated 9 years ago
- A structure-aware HTTP fuzzing library☆222Jan 12, 2026Updated 6 months ago
- Scripts I have made for blue team☆16Apr 1, 2018Updated 8 years ago
- ☆42Jun 2, 2026Updated last month
- Cyber-Informed Engineering addresses how cyberattacks on engineered systems threaten physical safety and reliability beyond data loss. Th…☆15Jun 1, 2026Updated last month
- Yet Another SCA tool☆13Nov 10, 2022Updated 3 years ago
- A Repo for the Magnetic case of the Sweep keyboard☆16Nov 19, 2023Updated 2 years ago
- Repro for Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!☆21Aug 25, 2024Updated last year
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- DC619/DC858 Mainframe Environment/Lab☆11Dec 9, 2021Updated 4 years ago
- A tool that adds reproducible UUIDs to YARA rules☆14May 15, 2026Updated 2 months ago
- ☆10Apr 2, 2022Updated 4 years ago
- Lutech TMS EHAT-NG☆14Jul 8, 2017Updated 9 years ago
- Official code for the paper entitled "Toward Intelligent and Secure Cloud: Large Language Model Empowered Proactive Defense"☆16Apr 10, 2025Updated last year
- ☆13May 18, 2022Updated 4 years ago
- I tried to replicate a complex AI pentest pipeline, using Kali MCP and HexStrike AI, and a proper setup Claude Code with augmented contex…☆27Jan 30, 2026Updated 5 months ago