Skip to content
Change the repository type filter

All

    Repositories list

    • Ruby
      0004Updated Apr 14, 2026Apr 14, 2026
    • Vulnerable REST API with OWASP top 10 vulnerabilities for security testing
      Python
      MIT License
      533002Updated Mar 14, 2026Mar 14, 2026
    • openssl

      Public
      TLS/SSL and crypto library
      C
      Apache License 2.0
      11k000Updated Mar 5, 2026Mar 5, 2026
    • A full insecure kubernetes application for testing security tools
      Python
      3030012Updated Feb 27, 2026Feb 27, 2026
    • Send usage data from your web app or site to PostHog, with autocapture.
      TypeScript
      Other
      248007Updated Feb 26, 2026Feb 26, 2026
    • Repo to store internally used composite actions
      0000Updated Feb 22, 2026Feb 22, 2026
    • OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
      TypeScript
      MIT License
      18k1064Updated Feb 11, 2026Feb 11, 2026
    • posthog

      Public
      🦔 PostHog provides open-source web & product analytics, session recording, feature flagging and A/B testing that you can self-host. Get started - free.
      Python
      Other
      2.7k0017Updated Feb 6, 2026Feb 6, 2026
    • saleor

      Public
      Saleor Core: the high performance, composable, headless commerce API.
      Python
      BSD 3-Clause "New" or "Revised" License
      6k0015Updated Feb 3, 2026Feb 3, 2026
    • streamlit

      Public
      Streamlit — A faster way to build and share data apps.
      Python
      Apache License 2.0
      4.2k001Updated Jan 6, 2026Jan 6, 2026
    • hugo-main

      Public
      Go
      Apache License 2.0
      1006Updated Nov 20, 2025Nov 20, 2025
    • vulnado

      Public
      Purposely vulnerable Java application to help lead secure coding workshops
      Java
      Other
      8250015Updated Oct 30, 2025Oct 30, 2025
    • mini-juice-shop
      JavaScript
      1008Updated Sep 11, 2025Sep 11, 2025
    • OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.
      HTML
      824000Updated Aug 1, 2025Aug 1, 2025
    • vulpy

      Public
      Vulnerable Python Application To Learn Secure Development
      Python
      MIT License
      5130020Updated Jul 15, 2025Jul 15, 2025
    • Chat2DB

      Public
      🔥🔥🔥AI-driven database tool and SQL client, The hottest GUI client, supporting MySQL, Oracle, PostgreSQL, DB2, SQL Server, DB2, SQLite, H2, ClickHouse, and more.
      Java
      Apache License 2.0
      2.8k002Updated Feb 24, 2025Feb 24, 2025
    • C#
      The Unlicense
      1000Updated Feb 21, 2025Feb 21, 2025
    • (Python Distribution) A carefully curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of…
      Python
      Other
      288000Updated Feb 4, 2025Feb 4, 2025
    • actions

      Public
      Corgea offers a suite of GitHub Actions designed to enhance the security and quality of your code. Our actions automate security scanning and quality checks, en…
      0000Updated Jan 10, 2025Jan 10, 2025
    • TypeScript
      MIT License
      1104Updated Sep 18, 2024Sep 18, 2024
    • Super vulnerable todo list application
      JavaScript
      Apache License 2.0
      3.4k005Updated Jun 13, 2024Jun 13, 2024
    • A Broken Application - Very Vulnerable!
      CSS
      MIT License
      3190010Updated Apr 4, 2024Apr 4, 2024
    • DVIA-v2

      Public
      Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security enthusiasts/professional…
      Swift
      MIT License
      231000Updated Mar 29, 2024Mar 29, 2024
    • a Damn Vulnerable Serverless Application
      JavaScript
      GNU General Public License v3.0
      2060010Updated Mar 27, 2024Mar 27, 2024
    • JavaScript
      376002Updated Mar 26, 2024Mar 26, 2024
    • CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool
      Python
      BSD 3-Clause "New" or "Revised" License
      753003Updated Mar 13, 2024Mar 13, 2024
    • action

      Public
      0100Updated Feb 27, 2024Feb 27, 2024
    • An intentionally designed broken web application based on REST API.
      Python
      GNU General Public License v3.0
      144001Updated Feb 7, 2024Feb 7, 2024
    • retriever

      Public
      Secure secret sharing through the browser using web crypto. No server required!
      HTML
      MIT License
      1822051Updated Jan 30, 2024Jan 30, 2024
    • Website with known vulnerabilities to use for various scanner tests
      C#
      4000Updated Dec 19, 2023Dec 19, 2023
    ProTip! When viewing an organization's repositories, you can use the props. filter to filter by custom property.