Repositórios

Repositórios de OWASP

Application Security Verification Standard

Último commit 17 de out. de 2023

 (2.324 stars) (586 forks) (0 issues indexadas) (0 good first issues abertas)

Último commit 22 de jan. de 2020

 (4 stars) (2 forks) (0 issues indexadas) (0 good first issues abertas)

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Último commit 6 de abr. de 2024

 (26.342 stars) (3.703 forks) (0 issues indexadas) (0 good first issues abertas)

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Último commit 8 de mai. de 2023

 (2.338 stars) (630 forks) (1 issue indexada) (1 good first issue aberta)

The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effectively address them.

Último commit 17 de jan. de 2024

 (1.794 stars) (1.526 forks) (3 issues indexadas) (3 good first issues abertas)

QRLJacking or Quick Response Code Login Jacking is a simple-but-nasty attack vector affecting all the applications that relays on “Login with QR code” feature as a secure way to login into accounts which aims for hijacking users session by attackers.

Último commit 7 de ago. de 2025

 (1.542 stars) (653 forks) (1 issue indexada) (1 good first issue aberta)

Último commit 28 de nov. de 2018

 (0 stars) (0 forks) (0 issues indexadas) (0 good first issues abertas)

Último commit 12 de set. de 2022

 (6 stars) (6 forks) (0 issues indexadas) (0 good first issues abertas)

Último commit 30 de jul. de 2022

 (6 stars) (5 forks) (0 issues indexadas) (0 good first issues abertas)

Official OWASP Top 10 Document Repository

Último commit 10 de nov. de 2023

 (3.906 stars) (800 forks) (0 issues indexadas) (0 good first issues abertas)

A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC

Último commit 30 de abr. de 2026

 (32 stars) (11 forks) (0 issues indexadas) (0 good first issues abertas)
OWASP/cwe-toolJavaScript

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.

Último commit 30 de abr. de 2026

 (63 stars) (23 forks) (0 issues indexadas) (0 good first issues abertas)

Kubernetes Security Testing Guide

Último commit 24 de jun. de 2020

 (26 stars) (5 forks) (0 issues indexadas) (0 good first issues abertas)

The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.

Último commit 18 de dez. de 2025

 (12.605 stars) (2.597 forks) (0 issues indexadas) (0 good first issues abertas)

Último commit 30 de jun. de 2020

 (35 stars) (20 forks) (0 issues indexadas) (0 good first issues abertas)

The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will help Java web developers defend against Cross Site Scripting!

Último commit 17 de nov. de 2025

 (536 stars) (123 forks) (0 issues indexadas) (0 good first issues abertas)

A documentation and tracking project with the goal of making package management systems more secure.

Último commit 5 de mar. de 2021

 (52 stars) (12 forks) (0 issues indexadas) (0 good first issues abertas)

A vulnerable version of Rails that follows the OWASP Top 10

Último commit 19 de ago. de 2023

 (836 stars) (584 forks) (0 issues indexadas) (0 good first issues abertas)

Vulnerable app with examples showing how to not use secrets

Último commit 19 de mai. de 2026

 (1.442 stars) (568 forks) (0 issues indexadas) (0 good first issues abertas)

Run Capture the Flags and Security Trainings with OWASP WrongSecrets

Último commit 19 de mai. de 2026

 (55 stars) (20 forks) (0 issues indexadas) (0 good first issues abertas)