
OWASP-Subtractive-Hardening-Top-10
The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…


PoC for CVE-2021-1056, related to GPU Container Security

A script to check if a container environment is vulnerable to container escapes via CVE-2022-0492

GitLab CI component for Trivy scanning

CVE-2024-0132 – Fully Weaponized NVIDIA Container Toolkit Exploit

Explot, Lab, Scanner - external and docker container, for SMongobleed-CVE-2025-14847 plus phoenix security uploader

CVE-2025-23266 – Fully Weaponized NVIDIA Container Toolkit Exploit

Proof of concept exploit for CVE-2025-9074 - Unauthenticated Docker Engine API container escape affecting Docker Desktop < 4.44.3 on Windows and…

Security toolkit for CVE-2025-55182 (React2Shell) — scan, detect, correlate, and test React Server Components RCE vulnerability

Patch Pulsar Docker images with Log4J 2.17.1 update to mitigate Apache Log4J Security Vulnerabilities including Log4Shell

CTWall (ChainThreatWall) platform helps Security, DevOps, and Product teams make risk decisions faster by using SBOM/BOM data to identify malware in…

Secure-by-default demo lab showing how container hardening (distroless images, non-root, read-only filesystem, runtime-injected secrets) can…

mailcow: Docker Container Exposure to Local Network

A full-stack AI Red Teaming platform securing AI ecosystems via Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.

A security-focused library OS supporting kernel- and user-mode execution

Vulnerable app with examples showing how to not use secrets

Metarget is a framework providing automatic constructions of vulnerable infrastructures.