
CVE-2026-64849.yaml
Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

Proof-of-concept exploit and advisory for CVE-2026-54356, a Budibase missing-authorization flaw that lets low-privilege users mint S3 pre-signed…

PoC + analysis for CVE-2026-54917 — SeaweedFS S3 gateway cross-bucket path traversal (CVSS 10.0, <4.30). Read/write any bucket via .. in the object…

Validates Google Maps API keys against 21 endpoints, revealing exposed services with PoC URLs, proxy support, and quiet mode for focused auditing.

find sensitive data leaking from ServiceNow instances.

Curated list and specification for eliminating high-impact attack paths across cloud, identity, network, and container environments, aligned with the…

Azure Sentinel detection lab for MCP attack patterns, providing 5 analytics rules and 7 KQL hunting queries against SSRF token theft, tool poisoning,…

Vulnerability Assessment Scanner with Report Generation

Community-driven catalog of testable security requirements for AI-enabled systems. Provides a structured checklist for developers and security…

Finds internet-exposed resources in an AWS account

Card game for threat modeling cloud and DevOps systems. Uses gamification to help teams identify security threats through structured play, teaching a…

OWASP-curated guide to the top 10 proactive security controls for Docker and containerized environments, covering threat modeling, configuration…

a Damn Vulnerable Serverless Application

Card game for software teams to identify security requirements in Agile, conventional, and formal development processes. Language, platform, and…

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

OWASP Ontology-driven Threat Modelling framework

Community-driven security requirements standard for IoT ecosystems, covering hardware, software, embedded applications, and communication protocols…

Web-based tool for assessing and tracking software security maturity using the OWASP SAMM and DSOMM models, with Docker support and automated mailing.