
actions-secrets
Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…

Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…

PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features…

Open-source, cross-platform, multi-purpose security auditing tool

KQL injection in adx-mcp-server via table_name — CVE-2026-33980 / CVSS 8.3

Proof-of-concept emulation and analysis of CVE-2025-1094, a critical PostgreSQL SQL injection vulnerability. Includes Docker-based lab setup, exploit…

JAW: A Graph-based Security Analysis Framework for Client-side JavaScript

CVE-2019-14900

Indexes C/C++ build artifacts into a queryable whole-program database, exposing AST, token, and IR-level APIs for code auditing and vulnerability…

Next-generation SQL static analyzer written in Rust. 282+ rules. Zero false positives. Security, performance, reliability, cost, compliance, quality.…

Sequelize JSON Cast SQL Injection

Proof-of-concept and detailed writeup for CVE-2026-51992, an SQL injection vulnerability in ClickHouse PostgreSQL dictionaries allowing arbitrary…

Cypher injection in Graphiti via unsanitized node_labels — CVE-2026-32247 / CVSS 8.1

Java source code generator that creates calling classes for Oracle PL/SQL package procedures, supporting various parameter types and automatic type…

Detailed CVE-2021-31856 report with PoC and code analysis for a SQL injection vulnerability in Meshery's pattern file API, enabling unauthenticated…

Assets Management System 1.0 is vulnerable to SQL injection via the id parameter in delete.php

version between CVE-2018-20433 and CVE-2019-5427

Open-source security audits for Supabase: a read-only MCP server, a CLI agent and a Claude Skill. Finds RLS misconfigurations, exposed keys and risky…