JavaSecLab is a comprehensive Java vulnerability platform| JavaSecLab是一款综合型Java漏洞平台,提供相关漏洞缺陷代码、修复代码、漏洞场景、审计SINK点、安全编码规范,覆盖多种漏洞场景,友好用户交互UI……
-
Updated
Jun 9, 2026 - Java
JavaSecLab is a comprehensive Java vulnerability platform| JavaSecLab是一款综合型Java漏洞平台,提供相关漏洞缺陷代码、修复代码、漏洞场景、审计SINK点、安全编码规范,覆盖多种漏洞场景,友好用户交互UI……
Non-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) in WordPress core 6.9.0-6.9.4 / 7.0.0-7.0.1
Node.js vulnerability labs
A structured library of web security flaws for humans and coding agents with vulnerable examples, attack paths, and secure replacements.
Provide a collection of deliberately vulnerable APIs along with corresponding challenges to help enhancing their skills in identifying, exploiting, and securing API vulnerabilities.
Automated vulnerable machine deployer for penetration testing training and CTF challenges. Deploys Docker containers with multiple configurable attack surfaces over SSH, managed through a web UI with real-time feedback.
本项目基于 Docker 搭建了一个用于复现和测试 sudo 本地权限提升漏洞 CVE-2025-32463 的实验环境。
Full-stack offensive security lab with a vulnerable Flask app, automated attack/recon modules, and reporting.
Automated Vulnerable Active Directory Lab inspired by OSCP-style enumeration and exploitation.
Halt Academy’s Docker-based vulnerable web application lab for practicing OS Command Injection in a controlled environment. Learn vulnerability discovery, payload testing, command execution, impact analysis, and mitigation techniques. Designed for cybersecurity students, penetration testers, bug bounty hunters, and security professionals.
AltaySec platformu için geliştirilmiş, sunucu taraflı şablon enjeksiyonu (SSTI) zafiyetlerini ve sömürme tekniklerini uygulamalı olarak gösteren laboratuvar çalışması.
Banking cybersecurity pentest simulation lab — fictional bank with intentionally vulnerable modules for OWASP Top 10 training. Education only.
A lab on the basic security checks to be implemented and a frontend to see its working
A FastAPI & Docker-powered interactive web security laboratory featuring Coder & Pentester modes, AI-assisted code analysis, and hands-on vulnerability scenarios.
Pikachu enhanced Web security lab with JWT, CORS, Clickjacking, Session Fixation, Host Header and Docker Lab.
Controlled NGINX HTTP/2 frame injection lab for CVE-2026-42926 patch validation and defensive research
Penetration Testing Sandbox simulated environment for bug bounty hunters. Master 8 common vulnerability challenges (SQLi, XSS, IDOR, SSRF, SSTI, XXE) in a 100% safe, browser-based lab
Deliberately vulnerable Node.js web application with MongoDB & Redis for security training, attack-defense exercises, and lab environments
Custom vulnerable VM (Ubuntu 14.04) designed for teaching multi-stage penetration testing. Features 10 interconnected challenges across Forensics, Web Exploitation (SQLi, XSS), Cryptography, and Kernel Exploitation (OverlayFS/CVE-2015-1328) to achieve full root compromise.
Add a description, image, and links to the vulnerability-lab topic page so that developers can more easily learn about it.
To associate your repository with the vulnerability-lab topic, visit your repo's landing page and select "manage topics."