
semgrep-rules
Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

C++ library for detecting cross-site scripting (XSS) vulnerabilities in URLs through pattern analysis, with server modules and command-line tools for…

Lightweight Protocol Buffers implementation in ANSI C for microcontrollers and memory-restricted embedded systems, enabling efficient serialization…

CVE-2020-27824 exploit reproduction environment for OpenJPEG JPEG 2000 codec, enabling vulnerability analysis, fuzzing, and binary exploitation…

C library for stream-oriented XML parsing, with a focus on analyzing and reproducing CVE-2024-28757 vulnerability in Expat 2.1.0.

Write your BPF programs in Go, not C. gobee transpiles a Go subset to BPF C and generates typed cilium/ebpf bindings.

C library for stream-oriented XML parsing with handler registration, supporting UTF-8/UTF-16 encoding, and autoconf-based build system. Includes…

Generate malicious files using recently published homoglyphic-attack (CVE-2021-42694)

Proof-of-concept exploit for CVE-2010-2387, a privilege escalation vulnerability in GNOME Display Manager (GDM). Includes C source code targeting the…

C library for parsing, editing, and saving EXIF metadata, with a focus on addressing CVE-2020-0198 in AOSP10.

C library for parsing, editing, and saving EXIF data, patched for CVE-2020-0181 to prevent heap buffer overflow in EXIF tag parsing.

Secure coding project, research on CVE-2019-17498 and implement a player score function written in C.

C library for parsing, editing, and saving EXIF data, with a focus on addressing CVE-2020-0452 in AOSP10. Provides API for metadata extraction and…

C library for stream-oriented XML parsing, providing handlers for parsing structures in documents. Includes xmlwf tool and supports UTF-16 encoding.

Reimplementation of CVE-2017-15361 checker in C

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

mobsfscan is a static analysis tool that can find insecure code patterns in your Android and iOS source code. Supports Java, Kotlin, Swift, and…

Modular software verification toolchain that translates LLVM IR into Boogie intermediate verification language for bounded and experimental unbounded…