
njsscan
Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

SASM - simple crossplatform IDE for NASM, MASM, GAS and FASM assembly languages

a static analysis tool for finding vulnerabilities in C/C++ source code

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

Simple Anti-cheat library for applications that use C++ on windows. #PastedProtection

It is a simple PoC of Improper Input Validation in python-gnupg 0.4.3 (CVE-2019-6690).

Educational demonstration of CVE-2007-4559 Python tarfile symlink attack with a script showing why os.path.realpath() fails to prevent extraction…

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

grep rough audit - source code auditing tool

[Moved to Codeberg] Simple local scanner for vulnerable log4j instances

Fast Go-based static scanner for detecting sensitive data (API keys, tokens, passwords) in JavaScript files and source code using regex patterns.

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool

Java source code generator that creates calling classes for Oracle PL/SQL package procedures, supporting various parameter types and automatic type…

Proof-of-concept exploit for CVE-2019-11358, a prototype pollution vulnerability in jQuery's extend method (versions <3.4.0). Demonstrates the attack…

Standalone Python script to verify if a project is affected by CVE-2025-55182 (React2Shell). Checks package.json dependencies and performs optional…

TinyXML 2.6.2 with fixes for CVE-2021-42260 and CVE-2023-34194

simple application with a (unreachable!) CVE-2022-45688 vulnerability

A simple simulation of the infamous CVE-2021-44228 issue.