
CVE-2007-4559-lab
Self-contained Docker lab demonstrating CVE-2007-4559 (TarSlip) directory traversal via Python's tarfile module. Includes vulnerable and fixed APIs,…

Self-contained Docker lab demonstrating CVE-2007-4559 (TarSlip) directory traversal via Python's tarfile module. Includes vulnerable and fixed APIs,…

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

We would like to request that all contributors please clone a *fresh copy* of this repository since the September 21st maintenance.

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

A service that analyzes docker images and scans for vulnerabilities

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

CLI tool that verifies Docker images for CVE-2018-8115 by checking layers for malicious files, helping ensure safe pulls from Docker Hub.

AI powered security analysis extension for Mobile Security Framework MobSF

Vulnerability Static Analysis for Containers

Detections for CVE-2021-44228 inside of nested binaries

A Public Package Scanner for The Community

Django application that performs SAST and Malware Analysis for Android APKs

Top-level repository for LFI: Practical, Efficient, and Secure Software-based Sandboxing

The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

A static analysis of vulnerabilities, Docker and Kubernetes cluster configuration detect toolkit based on the real penetration of cloud computing

Open-source secret scanner in Rust

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.