Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
-
Updated
Apr 16, 2026 - HTML
Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀
Best hands-on lab for learning the fundamentals of cybersecurity and penetration testing workflows also packaged as Docker containers for fast, safe setup.
Sample vulnerable code and its exploit code
Vulnerable Client-Server Application (VuCSA) is made for learning how to perform penetration tests of non-http thick clients. It is written in Java (with JavaFX graphical user interface) and contains multiple challenges including SQL injection, RCE, XML vulnerabilities and more.
VyAPI - A cloud based vulnerable hybrid Android App
Conviso Vulnerable Web Application is the OSS project from the Conviso Application Security for the community. The project represents a vulnerable web application to practice security testing and improve your learning in AppSec..
gRPC Goat is a "Vulnerable by Design" lab created to provide an interactive, hands-on playground for learning and practicing gRPC security.
An intentionally vulnerable AI chatbot to learn and practice AI Security.
Web Application Pentesting Lab with over 40 plus vulnerability, which covers all the owasp top 10 issues.
Examples of different vulnerabilities, in a variety of languages, shapes and sizes.
📧 [Research] E-Mail Injection: Vulnerable applications
OWASP Foundation Web Respository
LLMForge is probably the most modern AI vulnerability lab for OWASP VulnerableApp — real-LLM-backed labs for prompt injection, LLM-orchestrated BOLA, and RAG attacks.
This is a collection of vulnerable machines that can help you to learn hacking, pentesting and bug hunting. I know there are a lot of lists out there, but most of them are not updated regularly. So I decided to make on myself. Hope this will help you
Deliberately vulnerable MCP server (aka MCP Goat) for security training — 26 challenges across 4 difficulty levels (incl. a secure reference), a victim-agent harness, and one-command Docker deploy. Practice penetration testing against the Model Context Protocol.
Web/API, AI/LLM/MCP, and Web3/Blockchain security labs Android/iOS/Windows/macOS platforms plus PHP/Java/Node.js/Python stacks Cloud/Kubernetes, AD, IoT/ICS, CTF, and other specialized domains Continuously maintained collection of related resources
Self-hosted Dockerized pentest lab: five intentionally-vulnerable apps (store, bank, finance, SaaS + a dedicated AI/LLM lab) — 280+ vulns across OWASP Top 10 & the full LLM Top 10. The AI is a built-in deterministic offline engine: NO model, NO API key. A modern DVWA / Juice Shop alternative.
Several snippets of vulnerable code in different programming languages.
File Content Disclosure on Rails Test Case - CVE-2019-5418
To associate your repository with the vulnerable-app topic, visit your repo's landing page and select "manage topics."