
CVE-2025-3776
WordPress Verification SMS with TargetSMS Plugin <= 1.5 is vulnerable to Remote Code Execution (RCE)

WordPress Verification SMS with TargetSMS Plugin <= 1.5 is vulnerable to Remote Code Execution (RCE)

Source code for the Binaries of OWASP WrongSecrets

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

Research repository documenting LLM generalization ceilings in code security vulnerability detection, with cross-evaluation across synthetic and…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.


AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

OWASP ASST (Automated Software Security Toolkit) | A Novel Open Source Web Security Scanner.

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.

The Secure Coding Practices Quick-reference Guide from OWASP

OWASP Thick Client Application Security Verification Standard

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

The Secure Coding Dojo is a platform for delivering secure coding knowledge.
