
vulnerable-code-snippets
Twitter vulnerable snippets

Twitter vulnerable snippets

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

一个由AI生成的漏洞验证应用

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)


Executable security regression testing for agentic applications and MCP-integrated systems.

The AI Security Verification Standard (AISVS) focuses on providing developers, architects, and security professionals with a structured checklist to…

The OWASP Benchmark GitHub repo has moved to: https://github.com/OWASP-Benchmark/BenchmarkJava

A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Application Security Verification Standard

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.


AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

OWASP Certified Secure-Software Developer

The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)