Skip to content
Change the repository type filter

All

    Repositories list

    • Damn Vulnerable NodeJS Application
      SCSS
      Other
      8830014Updated Apr 12, 2026Apr 12, 2026
    • CX-AST

      Public
      Treinamento Checkmarx
      HCL
      00019Updated Apr 10, 2026Apr 10, 2026
    • Python
      MIT License
      0003Updated Apr 1, 2026Apr 1, 2026
    • pygoat

      Public
      intentionally vuln web Application Security in django
      HTML
      1.4k0059Updated Feb 25, 2026Feb 25, 2026
    • OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
      TypeScript
      MIT License
      18k002Updated Sep 12, 2025Sep 12, 2025
    • OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
      TypeScript
      MIT License
      18k001Updated Sep 12, 2025Sep 12, 2025
    • Java
      GNU General Public License v2.0
      1000Updated Jul 4, 2025Jul 4, 2025
    • Damn Vulnerable Python Web App
      Python
      MIT License
      747105Updated Jun 10, 2025Jun 10, 2025
    • Damn Vulnerable Java (EE) Application
      Java
      MIT License
      5500010Updated Jun 10, 2025Jun 10, 2025
    • OWASP Benchmark is a test suite designed to verify the speed and accuracy of software vulnerability detection tools. A fully runnable web app written in Java, i…
      Java
      GNU General Public License v2.0
      1.4k006Updated Apr 13, 2025Apr 13, 2025
    • A Broken Application - Very Vulnerable!
      CSS
      MIT License
      3190014Updated Apr 11, 2025Apr 11, 2025
    • Vulnerable Java based Web Application
      Java
      GNU General Public License v2.0
      514008Updated Apr 10, 2025Apr 10, 2025
    • aws-goat

      Public
      AWSGoat is a vulnerable by design infrastructure on AWS featuring the latest released OWASP Top 10 web application security risks (2021) and other misconfigurat…
      PHP
      MIT License
      1.5k0016Updated Apr 1, 2025Apr 1, 2025
    • An intentionally vulnerable Javascript app containing notable vulnerabilities in its dependencies.
      JavaScript
      Apache License 2.0
      37006Updated Mar 30, 2025Mar 30, 2025
    • Vulnerable app with examples showing how to not use secrets
      Java
      GNU Affero General Public License v3.0
      550007Updated Mar 28, 2025Mar 28, 2025
    • A very vulnerable implementation of a GraphQL API.
      TypeScript
      MIT License
      35008Updated Mar 27, 2025Mar 27, 2025
    • NodeGoat

      Public
      The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effecti…
      HTML
      Apache License 2.0
      2.4k007Updated Mar 27, 2025Mar 27, 2025
    • JavaScript
      10003Updated Mar 27, 2025Mar 27, 2025
    • Goatlin

      Public
      (aka Kotlin Goat) - an intentionally vulnerable Kotlin application
      Kotlin
      GNU General Public License v3.0
      177007Updated Mar 27, 2025Mar 27, 2025
    • WarGame

      Public
      JavaScript
      10006Updated Mar 27, 2025Mar 27, 2025
    • JavaScript
      10003Updated Mar 27, 2025Mar 27, 2025
    • Java
      6002Updated Mar 27, 2025Mar 27, 2025
    • WebGoat is a deliberately insecure application
      JavaScript
      Other
      7.6k005Updated Mar 27, 2025Mar 27, 2025
    • WebGoat is a deliberately insecure application
      JavaScript
      Other
      7.6k007Updated Mar 27, 2025Mar 27, 2025
    • 2ms

      Public
      Go
      Apache License 2.0
      32001Updated Mar 26, 2025Mar 26, 2025
    • OWASP WebGoat.NET
      C#
      734001Updated Jan 15, 2025Jan 15, 2025
    • Damn Vulnerable C# Application (API)
      C#
      2870703Updated Jan 15, 2025Jan 15, 2025
    • Java
      3000Updated Jan 13, 2025Jan 13, 2025
    • Go
      8001Updated Aug 22, 2024Aug 22, 2024
    • Go
      9001Updated Aug 22, 2024Aug 22, 2024
    ProTip! When viewing an organization's repositories, you can use the props. filter to filter by custom property.