
semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

OWASP Smart Contract Security (SCS) Project

OWASP Certified Secure-Software Developer

Project Wycheproof tests crypto libraries against known attacks.

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Pluggable linting tool to prevent committing credential.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

CVE-2022-31626, CVE-2024-2961, CVE-2019-6977, PHP security research

Checker for Lifetimes and other Refinement types

Executable security regression testing for agentic applications and MCP-integrated systems.

Unofficial revival of the well known .NET debugger and assembly editor, dnSpy

Reproducer for CVE-2026-43867 — Apache Camel camel-pqc AwsSecretsManagerKeyLifecycleManager unsafe key-metadata deserialization (RCE)

Reproducer for CVE-2026-43866 — Apache Camel camel-jms forged DefaultExchangeHolder bypass of the CVE-2026-40860 deserialization filter…

Reproducer for CVE-2026-43865 — Apache Camel camel-hazelcast default-configured instance unsafe Java deserialization (RCE)

Reproducer for CVE-2026-40860 — Apache Camel camel-jms/sjms/amqp JMS ObjectMessage unsafe deserialization (RCE)

Reproducer for CVE-2026-40859 — Apache Camel camel-netty-http / camel-vertx-http producer-side unsafe deserialization of HTTP response bodies (RCE)

Reproducer for CVE-2026-40453: Apache Camel case-variant Camel header injection (incomplete fix of CVE-2025-27636)