
semgrep-rules
Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

Macro-header for compile-time C obfuscation (tcc, win x86/x64)

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Fuzzing Framework for Modules in Apache HTTPD Server

CVE-2026-52887 — NocoBase SQL injection -> PostgreSQL-superuser RCE (myInAppChannels:list filter, CVSS 10.0). Author PoC + source analysis + docker…

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

Isolated JavaScript sandbox for Node.js that runs untrusted code with restricted access to built-in modules and host resources via Proxy-based…

Nuclio Dashboard (NOP mode) accepts unauthenticated POST /api/functions. The spec.handler field isn't path-validated, so…

Evidence-driven C/C++ vulnerability remediation pipeline + http-parser case study (CVE-2024-22019-class). Python core, React 19 console, 17-test…

Security Advisory: Insufficient Access Controls Allow for Unauthorized Room Deletion (Let's Chat)

A Python-based static patch analysis tool for studying the root cause and remediation of CVE-2021-41773 (Apache HTTP Server Path Traversal) by…

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

CVE-2026-0006: Heap buffer overflow PoC for libopenapv (Android APV codec) - CVSS 9.8

To reproduce CVE-2021-31630

VulnAgent-X: A Layered Agentic Framework for Repository-Level Vulnerability Detection