https://owasp.org/www-project-application-security-verification-standard/
Found this interesting list: https://list.latio.tech/
On the open source side, there is https://www.dependencytrack.org/