
alibi
Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

Scans code diffs with context to build an impact graph and uses LLMs to find vulnerabilities, supporting multi-repo scans and CI gating with SARIF…

Stored XSS via Location Title in DPCalendar Free

LuaJIT FFI bindings for libinjection, providing SQL injection and XSS detection with context-specific APIs for web application security.

Demonstrates a stored XSS vulnerability in lunary-ai/lunary's Analytics component, where unsanitized NEXT_PUBLIC_CUSTOM_SCRIPT injection leads to…

Drop-in WordPress plugin that blocks the vulnerable Demo Import handler in FunnelForms Pro to mitigate Remote Code Execution (CVE-2026-39440).

WordPress Passster Plugin <= 4.2.18 is vulnerable to Cross Site Scripting (XSS)

Proof-of-concept and detailed writeups for CVE-2024-57487 (authenticated RCE via file upload) and CVE-2024-57488 (stored XSS) in Online Car Rental…

YAML-based proof-of-concept for CVE-2025-59528, demonstrating remote code execution in Flowise via the CustomMCP node's unsafe JavaScript evaluation.

A wrapper around grep, to help you grep for things

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…


Maps execution-coverage data onto Ghidra disassembly to highlight visited code paths and accelerate reverse-engineering workflows.

Xyntia, the black-box deobfuscator

Pishi is a code coverage tool like kcov for macOS.

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Fuzzing Framework for Modules in Apache HTTPD Server

ADT is a toolset designed to help model application behavior, research and test security vulnerabilities, and facilitate reversing hostile code.