
CVE-2025-3776
WordPress Verification SMS with TargetSMS Plugin <= 1.5 is vulnerable to Remote Code Execution (RCE)

WordPress Verification SMS with TargetSMS Plugin <= 1.5 is vulnerable to Remote Code Execution (RCE)

This is a defunct code base. The project is located at: https://github.com/WebGoat

Source code for the Binaries of OWASP WrongSecrets

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

Automated Web Vulnerability Assessment of DVWA using OWASP ZAP to identify and analyze critical security flaws like Remote Code Execution…

Research repository documenting LLM generalization ceilings in code security vulnerability detection, with cross-evaluation across synthetic and…

C-based Android static analysis framework for decompilation, secret detection, endpoint discovery, permission analysis, and native library scanning…

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.

OWASP Thick Client Application Security Verification Standard

A TypeScript package that provides AI-powered agents for Application Security (AppSec) tasks, built on top of the frontier models.

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

The Secure Coding Dojo is a platform for delivering secure coding knowledge.

A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC

Vulnerability Patterns Detector for C# and VB.NET

Silent dependency injection through AI documentation pipelines. 240 isolated Docker runs proving Context Hub's zero-sanitization MCP server lets…

A vulnerable version of Rails that follows the OWASP Top 10