Skip to content

A curated list of vulnerable web applications.

Notifications You must be signed in to change notification settings

CyVenom/vuln-web-apps

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

25 Commits
 
 

Repository files navigation

Awesome Vulnerable Web Applications

Name URL Technology Creds (role:user:password)
Acunetix Acuforum http://testasp.vulnweb.com/ IIS, ASP, Microsoft SQL Server unknown
Acunetix Acublog http://testaspnet.vulnweb.com/ IIS, ASP.NET, Microsoft SQL Server unknown
Acunetix SecurityTweets http://testhtml5.vulnweb.com/ nginx, Python, Flask, CouchDB admin:admin:1234
Acunetix Acuart http://testphp.vulnweb.com/ Apache, PHP, MySQL unknown
Broken Crystals https://brokencrystals.com/ Node.js admin:admin
bWAPP http://bwapp.ywnxs.com/ Ubuntu, Nginx, PHP user: bee:bug
Cenzic crackmebank http://crackme.cenzic.com/ CentOS, Apache, PHP unknown
Firing Range https://public-firing-range.appspot.com/ Google App Engine unknown
PortSwigger Gin & Juice Shop https://ginandjuice.shop/ AWS unknown
Google Gruyere http://google-gruyere.appspot.com/start Python, Google App Engine unknown
HackYourselfFirst http://hack-yourself-first.com/ IIS, ASP.NET unknown
HP freebank http://zero.webappsecurity.com/ Apache Tomcat unknown
IBM Altoro Mutual http://demo.testfire.net/ IIS, ASP.NET user:jsmith:Demo1234
IBM AltoroJ Mutual http://www.altoromutual.com:8080/ Tomcat, Java 3.1 user:jsmith:Demo1234
IBM Hard Altoro Mutual http://hard.altoromutual.com/ Tomcat, Java 3.1, MegaScript user:jsmith:Demo1234
OWASP Juice Shop https://juice-shop.herokuapp.com/ Node.js unknown
OWASP NodeGoat http://nodegoat.herokuapp.com/ Node.js unknown
Rapid7 Hackazon http://hackazon.webscantest.com/ Apache, PHP, Ajax, JSONm XML, Gwt, AMF admin:admin:123456
Rapid7 WebScanTest http://webscantest.com/ Apache, PHP user:testuser:testpass
Testsparker ASP.NET http://aspnet.testsparker.com/ Windows, IIS, ASP.NET, Microsoft SQL Server unknown:[email protected]:theturingtest
Testsparker PHP http://php.testsparker.com/ Windows, Apache, PHP, MySQL unknown:admin:admin123456
Testsparker SPA (Angular) http://angular.testsparker.com/ Ubuntu, Apache, PHP, Angular 5, MySQL unknown
XSS Test https://brutelogic.com.br/knoxss.html unknown
Pentest-Ground https://pentest-ground.com Apache, Nginx, Redis unknown

About

A curated list of vulnerable web applications.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published