
CVE-2026-3456-OAuth2-PKCE-Race-Condition-Account-Takeover-
Python PoC for CVE-2026-3456 demonstrating OAuth2 PKCE race-condition account takeover, with a vulnerable auth server and concurrent code-verifier…

Python PoC for CVE-2026-3456 demonstrating OAuth2 PKCE race-condition account takeover, with a vulnerable auth server and concurrent code-verifier…

Proof-of-concept exploit resources for CVE-2026-19650 and CVE-2026-19478 targeting a GitLab GraphQL vulnerability, intended for authorized research,…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of…

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

Run untrusted AI code safely, fast

Apache APISIX Remote Code Execution (CVE-2022-24112) proof of concept exploit

CVE-2026-60137Temporary Emergency Mitigation for CVE-2026-60137 & CVE-2026-63030 (wp2shell)

CVE-2026-32662: Active Debug Code in Production — Gardyn Home Kit (ICSA-26-055-03)

Cursor plugin for Hono v4 (TypeScript edge web framework). 59 LLM regressions with BAD/CORRECT pairs. Pinned to hono ^4.12.19 (>= 4.9.7 for…

Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security…

Scan codebases and GCP projects for exposed API credentials

Java core library for FHIR specification with validator, version converters, and object models for R2 through R5, used in HAPI servers and HL7…

OPNsense GUI, API and systems backend

CLI tool that audits OpenAPI specifications, validates them against best practices, and runs automated security tests to detect vulnerabilities and…

OWASP Secure Agent Playbook Project

PlaceOS authentication service and API gatekeeper.

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)