8 Lessons, Kick-start Your Cybersecurity Learning.
-
Updated
Nov 18, 2025 - HTML
8 Lessons, Kick-start Your Cybersecurity Learning.
Open-Source Unified Vulnerability Management, DevSecOps & ASPM
vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.
OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.
ZAP Add-ons
A vulnerable version of Rails that follows the OWASP Top 10
OWASP BLT - Bug Logging Tools
In progress rough solutions to bWAPP / bee-box
OWASP Code Review Guide Web Repository
OWASP Zed Attack Proxy project landing page.
OWASP Foundation Threat Dragon Project Web Repository
The source of ZAP website
OWASP Citizen Development Top 10
Integrates OWASP Zed Attack Proxy reports into SonarQube
The OWASP Vulnerable Web Applications Directory Project (VWAD) is a comprehensive and well maintained registry of all known vulnerable web applications currently available.
OWASP SecureFlag Open Platform
Add a description, image, and links to the appsec topic page so that developers can more easily learn about it.
To associate your repository with the appsec topic, visit your repo's landing page and select "manage topics."