
Nettacker
Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

Interactive platform linking security standards and guidelines for designing, developing, testing, and procuring secure software. Provides a unified…

Pen Test Report Generation and Assessment Collaboration

Intelligent Component Analysis platform that leverages SBOMs to identify and reduce software supply chain risk through continuous vulnerability…

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

An open source threat modeling tool from OWASP

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.


The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

OWASP Smart Contract Security (SCS) Project

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

OWASP Certified Secure-Software Developer

Detects CVE-2026-19478 in GitLab CE/EE with a non-destructive Nuclei template that triggers the GraphQL fallback-field method invocation via touch…

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

Collaborative application security testing between humans and agents via CLI and MCP

Vulnerable app with examples showing how to not use secrets