
DVWA-ZAP-PENTEST
Web application security assessment of DVWA using OWASP ZAP — vulnerability scanning, RCE (CVE-2012-1823) analysis, and remediation report.

Web application security assessment of DVWA using OWASP ZAP — vulnerability scanning, RCE (CVE-2012-1823) analysis, and remediation report.

Curated collection of bug bounty writeups covering OWASP Top 10 vulnerabilities, including XSS, SQLi, SSRF, and RCE, for educational learning and…

OWASP VBScan is a Black Box vBulletin Vulnerability Scanner

OWASP Ontology-driven Threat Modelling framework

OWASP Thick Client Application Security Verification Standard

OWASP framework providing structured security capabilities for software products, derived from regulatory and industry standards analysis to guide…


CVE-2024-26026: BIG-IP Next Central Manager API UNAUTHENTICATED SQL INJECTION

[CVE-2016-4014] SAP Netweaver AS JAVA UDDI Component XML External Entity (XXE)

Exploit script for CVE-2021-4191 that enumerates GitLab users via the GraphQL API, useful for security assessments and validating exposure.

Reproducer for CVE-2026-46587: Apache Camel camel-couchbase CCB_* header injection enabling document disclosure, tampering, and TTL-forced data…

Reproduction of a high severty security problem that allows XXE (XML eXternal Entity) attacks on Ktor's XML serialization.

A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10…

Project focused on governance and risk in application security, providing resources and frameworks for security maturity and risk management.

A multi threaded Python script designed to brute force directories and files names on webservers.


A curated library of security prompts for AI-assisted security testing, threat modeling, and educational exercises.
