
VulnReach
Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

Detailed technical analysis of CVE-2026-47777, a high-severity authorization bypass in Mastodon's Featured Collections federation pipeline, including…

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

Workaround guide for CVE-2022-41923 privilege management vulnerability in Grails Spring Security Core plugin, providing patched filter definitions…

This skill helps Claude write secure code and prevent common vulnerabilities.

Claude Skill that audits your projects for RLS misconfigurations, exposed keys, auth bypasses, and storage vulnerabilities. 27 anti-patterns sourced…

A security-patched fork of the legacy ClickFunnels Classic WordPress plugin. Fixes critical Stored XSS vulnerabilities (CVE-2022-4782) while…

PHP 8.4+ security library (mirror)

A security-hardened fork of Crowdsignal Forms. Patches CVE-2025-69015 (Broken Access Control), modernizes for PHP 8.2+, and enforces strict…

Open-source security gateway & static scanner for AI agents. Enforce role-based access control (RBAC), human-in-the-loop approvals, segregation of…

OpenSSL 1.0.1g source code with CVE-2015-1791 patch, providing SSL/TLS and cryptographic library for secure communications.

OWASP Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input…

authz research - CVE-2026-3306 fix coverage

OWASP Foundation Web Respository


IDOR + Stored XSS via Broken Object-Level Authorization in JoomGallery