
owasp-java-encoder
The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

Pluggable linting tool to prevent committing credential.

OWASP Secure Agent Playbook Project

agent runtime security - zero trust, zero setup, zero latency.

OWASP Certified Secure-Software Developer

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Using Struts2 and PowerShell to recreate CVE-2017-5638 OGNL Injection vulnerability.

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

Apache RAT (Release Audit Tool) Gradle Plugin

CodeQL detector for CVE-2022-2869 root cause (CWE-191 unsigned underflow) using control-flow/range analysis to identify vulnerable patterns without…

Unofficial revival of the well known .NET debugger and assembly editor, dnSpy

Project Wycheproof tests crypto libraries against known attacks.

OWASP Smart Contract Security (SCS) Project

Found a 0-Day in Ghidra: Shared Project File Became a Code Execution Vector

CVE-2022-31626, CVE-2024-2961, CVE-2019-6977, PHP security research

Checker for Lifetimes and other Refinement types