
mcpshield
Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)
OWASP Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input…

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

OWASP teaching modules covering application security fundamentals including risk management, secure software development, and operations security for…


Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

AzureGoat : A Damn Vulnerable Azure Infrastructure

A fast WordPress plugin enumeration tool

A wordlist of API names for web application assessments

OWASP Autonomous Penetration Testing Standard

Research on GraphQL from an AppSec point of view.

PyJFuzz - Python JSON Fuzzer

Analyze HTTP requests to minimize risks of HTTP Desync attacks (precursor for HTTP request smuggling/splitting).

Burp Extension for testing authorization issues. Automated request repeating and parameter value extraction on the fly.

OWASP SecurityRAT (version 1.x) - Tool for handling security requirements in development

Proof-of-concept exploit for CVE-2022-23808, a stored XSS vulnerability in phpMyAdmin 5.1.1 setup script, with payload and reproduction steps for…

Automated penetration testing framework for REST APIs with OpenAPI-driven test generation, 32 OWASP-based security tests, and built-in access control…