


Official repository for the AppSecDC 2019 conference, hosting presentation materials, resources, and curated content from the OWASP AppSecDC event.

[CVE-2016-4014] SAP Netweaver AS JAVA UDDI Component XML External Entity (XXE)

OWASP tool for systematic threat modeling using the Model Context Protocol to identify and mitigate security risks in software architecture.

Proof-of-concept exploit for CVE-2026-21876 demonstrating multipart charset bypass of OWASP CRS WAF in Flask, ASP.NET, and Spring Boot applications.

Reproducer for CVE-2026-46588: Apache Camel camel-couchdb CouchDb* header injection (operation confusion) subverting a write-only endpoint into read…

Reproduction of a high severty security problem that allows XXE (XML eXternal Entity) attacks on Ktor's XML serialization.

OWASP VBScan is a Black Box vBulletin Vulnerability Scanner

OWASP Ontology-driven Threat Modelling framework

OWASP Thick Client Application Security Verification Standard

CVE-2024-26026: BIG-IP Next Central Manager API UNAUTHENTICATED SQL INJECTION

Proof-of-concept demonstrating log injection and poisoning in Splunk via crafted URL parameters, highlighting OWASP log injection risks.

Exploit script for CVE-2021-4191 that enumerates GitLab users via the GraphQL API, useful for security assessments and validating exposure.

Reproducer for CVE-2026-46587: Apache Camel camel-couchbase CCB_* header injection enabling document disclosure, tampering, and TTL-forced data…

Apache APISIX apisix/batch-requests RCE

A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10…

O-Saft - OWASP SSL advanced forensic tool

Project focused on governance and risk in application security, providing resources and frameworks for security maturity and risk management.