Skip to content
Change the repository type filter

All

    Repositories list

    • Damn Vulnerable Bank is designed to be an intentionally vulnerable android application. This provides an interface to assess your android application security hacking skills.
      Java
      MIT License
      1860023Updated Dec 11, 2024Dec 11, 2024
    • Goatlin

      Public
      (aka Kotlin Goat) - an intentionally vulnerable Kotlin application
      Kotlin
      GNU General Public License v3.0
      132006Updated Dec 10, 2024Dec 10, 2024
    • DVAA

      Public
      Damn Vulnerable Android App
      JavaScript
      20021Updated Nov 18, 2024Nov 18, 2024
    • Vulnerable Android application for developers and security enthusiasts to learn about Android insecurities
      Java
      MIT License
      4600012Updated Nov 1, 2024Nov 1, 2024
    • WaTF-Bank

      Public
      WaTF Bank - What a Terrible Failure Mobile Banking Application for Android and iOS
      C
      MIT License
      420010Updated Oct 28, 2024Oct 28, 2024
    • Exploited a bank application to find vulnerabilities in the app using Drozer, IDA-Pro and X-posed framework
      Python
      10010Updated Oct 28, 2024Oct 28, 2024
    • mfva

      Public
      the gangsta vulnerable android app
      Java
      GNU General Public License v3.0
      150010Updated Nov 21, 2023Nov 21, 2023
    • ovaa

      Public
      Oversecured Vulnerable Android App
      Java
      BSD 2-Clause "Simplified" License
      1780010Updated Nov 20, 2023Nov 20, 2023
    • pivaa

      Public
      Created by High-Tech Bridge, the Purposefully Insecure and Vulnerable Android Application (PIVAA) replaces outdated DIVA for benchmark of mobile vulnerability scanners.
      Java
      GNU General Public License v3.0
      640010Updated Oct 30, 2023Oct 30, 2023
    • Application for showcasing Android application Crypto vulnerabilities
      C
      MIT License
      2005Updated Sep 4, 2023Sep 4, 2023
    • A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.
      Kotlin
      Apache License 2.0
      146005Updated Sep 4, 2023Sep 4, 2023
    • Shows some vulnerability of app content deep linking using intents
      Java
      BSD 3-Clause "New" or "Revised" License
      1006Updated Sep 4, 2023Sep 4, 2023
    • Java
      GNU General Public License v3.0
      20010Updated Sep 4, 2023Sep 4, 2023
    • Beetlebug

      Public
      Beetlebug is an open source insecure Android application with CTF challenges built for Android Penetration Testers and Bug Bounty hunters.
      Java
      17009Updated Sep 4, 2023Sep 4, 2023
    • Intentionally Vulnerable Mobile Application
      4006Updated Sep 4, 2023Sep 4, 2023
    • Dirty Mobile is a vulnerable Android application.
      Java
      1005Updated Sep 4, 2023Sep 4, 2023
    • The MAS Crackmes aka. UnCrackable Apps, a collection of mobile reverse engineering challenges part of the OWASP MAS project.
      C
      GNU Lesser General Public License v3.0
      12005Updated Sep 4, 2023Sep 4, 2023
    • Buggyapp

      Public
      Buggyapp is an vulnerable android application. This app can be used by pentesters, security researchers to practice Android application pentesting. This is build for beginners to learn basics about Android application pentesting
      Java
      50010Updated Sep 4, 2023Sep 4, 2023
    • EVABS

      Public
      An open source Android application that is intentionally vulnerable so as to act as a learning platform for Android application security beginners.
      CMake
      450012Updated Sep 4, 2023Sep 4, 2023
    • iahaa1

      Public
      Iahaa1: Insecure as heck Android app (version 1)
      Java
      MIT License
      2005Updated Sep 4, 2023Sep 4, 2023
    • A damn vulnerable Kotlin Android Application
      Kotlin
      GNU General Public License v3.0
      100010Updated Sep 4, 2023Sep 4, 2023
    • Application for showcasing Android PinLock related vulnerabilities
      Java
      MIT License
      1005Updated Sep 4, 2023Sep 4, 2023
    • Application for showcasing Android Platform check vulnerabilities
      Java
      MIT License
      1005Updated Sep 4, 2023Sep 4, 2023
    • Insecure Android Application for testing Biometric bypasses
      Java
      Apache License 2.0
      3005Updated Sep 4, 2023Sep 4, 2023
    • Sample application to test for vulnerability to MiM redirect attacks
      Java
      1007Updated Sep 4, 2023Sep 4, 2023
    • vuln-apps

      Public
      Vulnerable Android applications
      Java
      1005Updated Aug 9, 2023Aug 9, 2023
    • Android client application.
      Java
      GNU General Public License v3.0
      163000Updated Jun 19, 2023Jun 19, 2023
    • damn-exploitable-android-app-apk
      5000Updated Jun 9, 2023Jun 9, 2023
    • DIVA Android - Damn Insecure and vulnerable App for Android
      Java
      GNU General Public License v3.0
      287108Updated Mar 6, 2023Mar 6, 2023
    • A Vulnerable Android app developed to learn more about android development mecanisms.
      Java
      10010Updated Mar 6, 2023Mar 6, 2023