
radare2
UNIX-like reverse engineering framework and command-line toolset

UNIX-like reverse engineering framework and command-line toolset

Android platform framework patch for CVE-2023-21281, addressing a security vulnerability in the Android framework.

Exploit for CVE-2022-22965 (Spring4Shell) targeting Spring Framework versions vulnerable to remote code execution via classLoader manipulation.

Ghidra is a software reverse engineering (SRE) framework

MARA is a Mobile Application Reverse engineering and Analysis Framework. It is a toolkit that puts together commonly used mobile application reverse…

Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

AndroBugs Framework is an efficient Android vulnerability scanner that helps developers or hackers find potential security vulnerabilities in Android…

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

WordPress wp2shell pre-auth RCE exploit kit (CVE-2026-63030 + CVE-2026-60137)

An easy-to-learn/use static analysis framework for Java and Android

(CVE-2017-9841) PHPUnit_eval-stdin_php Remote Code Execution

Scala-based static analysis framework for Android and Java bytecode with flow analysis, decompilation, and native code analysis via symbolic…

Exploit for Apache Struts CVE-2017-9805, a remote code execution vulnerability in the REST plugin. Enables penetration testing and security…

Spring4Shell is a critical RCE vulnerability in the Java Spring Framework and is one of three related vulnerabilities published on March 30

Android framework patch for CVE-2023-21284, addressing a security vulnerability in AOSP 10.

ReactGuard provides framework- and vulnerability-detection tooling for CVE-2025-55182 (React2Shell)

Proof-of-concept exploit for CVE-2025-51482, demonstrating remote code execution via unsafe exec() usage and sandbox bypass in the Letta AI agent…

Android platform framework repository containing a patch or analysis for CVE-2023-21288, a vulnerability in the Android framework.