
core
OPNsense GUI, API and systems backend

OPNsense GUI, API and systems backend

Powerful protection for AI agents - Open-source security and cost tracking for AI applications


Zero-trust networking platform that makes services invisible with cryptographic identity, policy-based access, and end-to-end encryption. Replaces…

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

Open Source Vulnerability Management Platform

Kubernetes policy engine with OPA-based admission control, mutation, and audit for enforcing security and compliance configurations.

A Software as a Service (SaaS) log collection framework.

Minimal Python PoC for CVE-2026-40179: injects a malicious metric name via unauthenticated Prometheus remote_write to trigger stored XSS in the web…

Proof-of-concept exploit for CVE-2026-64849: triggers SSRF in MLflow webhook API via crafted POST, fetching cloud instance metadata from…

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Your gateway to OWASP. Discover, engage, and help shape the future!

CVE-2026-39154 · Stored XSS in CometChat JS SDK

PoC exploit for unauthenticated RCE in EITS Admin Dashboard v2.4.0 via command injection in /api/v1/debug, allowing arbitrary OS command execution on…

PoC for CVE-2026-73519 - WolfStack hardcoded cluster secret leads to unauthenticated RCE (CVSS 9.8)

PoC exploit for critical Budibase auth bypass: unanchored webhook regex lets attackers append ?/webhooks/trigger, reach protected APIs, and chain…