OWASP Security Projects Catalog
Comprehensive threat guides, vulnerability frameworks, and defense documentation maintained by the Open Web Application Security Project (OWASP).
OWASP API Security Top 10
Detailed analysis of API-specific security threats including BOLA (Broken Object Level Authorization), BFLA, and API rate limiting failures.
OWASP Top 10 Web Application Risks
The standard awareness document for developers and web application security, covering Injection, Broken Access Control, and SSRF.
OWASP Smart Contract Top 10 (2025)
Security flaws in Web3, EVM smart contracts, reentrancy attacks, flash loan exploits, and decentralized finance (DeFi) vulnerabilities.
OWASP Top 10 for LLM Applications
Critical vulnerabilities in AI and Large Language Models, including Prompt Injection, Data Poisoning, Sensitive Information Disclosure, and Model Denial of Service.
OWASP Mobile Top 10
Security risks impacting iOS and Android mobile software, insecure data storage, improper credential usage, and binary tampering.