
Tiredful-API
An intentionally designed broken web application based on REST API.

An intentionally designed broken web application based on REST API.

Software Component Verification Standard (SCVS)

OWASP enumeration of common security and privacy weaknesses in mobile applications, serving as a reference bridging the MASVS verification standard…

☸The first ever dependency-aware GraphQL API testing tool!

A vulnerable version of Rails that follows the OWASP Top 10

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

Automated CORS misconfiguration scanner that tests Origin header injection, wildcard reflection, and credential leakage across web applications and…

Demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI's chat API, allowing attackers to consume other users'…

This Burp Suite extension allows you to customize header with put a new header into HTTP REQUEST BurpSuite (Scanner, Intruder, Repeater, Proxy…

Deploy web honeypots to capture emerging attack data, analyze ModSecurity audit logs via ELK, and share threat intelligence with MISP for…

SDK for querying the Intelligence X search engine and data archive, supporting selectors like email, domain, IP, and phone. Includes API wrappers in…

A rapid HTTP downgrade smuggling scanner written in Go.

End to End testing of Web, API, Cloud, Events and Security

OWASP Foundation Web Respository

C-based Android static analysis framework for decompilation, secret detection, endpoint discovery, permission analysis, and native library scanning…

Given JSON-like content, The JSON Sanitizer converts it to valid JSON.

DonkAI is a hands-on lab for the OWASP Top 10 for LLM Applications (2025) - no real LLM required.

Technical analysis and Proof-of-Concept for CVE-2026-60206, a critical Oracle WebLogic Server SAML authentication bypass vulnerability.