
FIASSE
A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

The Secure Coding Framework

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

MARA is a Mobile Application Reverse engineering and Analysis Framework. It is a toolkit that puts together commonly used mobile application reverse…



OWASP Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

OWASP ASST (Automated Software Security Toolkit) | A Novel Open Source Web Security Scanner.

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Reproduction of a high severty security problem that allows XXE (XML eXternal Entity) attacks on Ktor's XML serialization.

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

Automated testing suite with live traffic record and replay

CVE-2024-11972 in Hunk Companion <1.9.0 allows unauthenticated attackers to exploit insecure REST API endpoints and install vulnerable plugins,…

Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain

一个由AI生成的漏洞验证应用

OWASP Smart Contract Security (SCS) Project