
lua-ffi-libinjection
LuaJIT FFI bindings for libinjection, providing SQL injection and XSS detection with context-specific APIs for web application security.

LuaJIT FFI bindings for libinjection, providing SQL injection and XSS detection with context-specific APIs for web application security.

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

Ruby-based exploit for CVE-2020-15169, demonstrating a specific web application vulnerability with proof-of-concept code for security testing and…

Do You Know What's In Your Python Packages? A Tool for Visualizing Python Package Registry Security Audit Data

Proof-of-concept exploit for CVE-2024-24725, demonstrating a web application vulnerability with PHP-based exploitation code for security testing and…

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Application Security Verification Standard

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

Open-source Interactive Application Security Testing (IAST) tool that passively instruments Java applications to detect vulnerabilities and…

OWASP Thick Client Application Security Verification Standard

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

A curated list of resources, practice questions, and study materials to help you prepare for Application Security (AppSec) interviews

Educational exploit demo for CVE-2018-1263 (phpMyAdmin RCE/LFI). Includes vulnerable environment setup via Docker and step-by-step attack walkthrough…

Repository containing the DSpace 4.4 source code with a focus on CVE-2016-10726, providing a reference for vulnerability analysis and educational…