
osv-scanner
Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Snyk CLI scans and monitors your projects for security vulnerabilities.

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

Static analysis tool that detects malicious dependencies in CI/CD pipelines using pattern matching and AST analysis, with a traffic-light risk…

Django application that performs SAST and Malware Analysis for Android APKs

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

awslabs/sockeye Code injection via unsafe YAML loading CVE-2021-43811

It is a simple PoC of Improper Input Validation in python-gnupg 0.4.3 (CVE-2019-6690).

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Find, verify, and analyze leaked credentials

The community's most comprehensive, continuously-updated index of research on Large Language Models for software vulnerability detection — papers…

Run iOS apps without actually installing them!

Security scanner for AI agents, MCP servers and agent skills.

Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret…

Ghidra is a software reverse engineering (SRE) framework

A benchmark for evaluating AI agents on fixing real-world security vulnerabilities.

Proof-of-concept for authenticated arbitrary file upload in Sitecore 10.3, enabling webshell deployment and remote code execution via the import…

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.