PentesterLab
Hands-on platform for learning web application security through realistic vulnerable code and documented CVEs. Covers exploitation techniques and code review methodology. Useful for developers who want to understand how real vulnerabilities work and for security testers building practical skills. The CVE-focused approach grounds learning in actual attack patterns rather than abstract concepts.