
XcInspector
A macOS app to scan Xcode project files for possible security issues.

A macOS app to scan Xcode project files for possible security issues.

Vulnerabilities in the Git node allowed authenticated users with permission to create or modify workflows to execute arbitrary system commands or…

Created after the disclosure of CVE-2021-44228. Bash script that detects Log4j occurrences in your projects and systems, allowing you to get insight…

Python Wheel File Security Scanner — scan .whl files for security issues before installation. Detects path traversal (CVE-2026-24049), RECORD…

Detailed write-up and proof-of-concept for CVE-2026-35570, a sandbox bypass in openclaude v0.1.7 allowing path traversal to read and write arbitrary…

Proof-of-concept demonstrating a hardlink path traversal in the tar npm package, allowing overwrite of files outside the extraction directory via…

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

Adding this GitHub Action will scan your repository for sensitive data in your source code. We find things like passwords, server host strings, API…

A library for creating, reading and editing PE files and .NET modules.

MAGNOLIA-8281: FreeMarker Restriction Bypass 2 in Magnolia CMS

Fast code security scanner designed for manual security code review by experts. Outputs line-referenced findings to text files for easy filtering and…

VisualCodeGrepper - Code security scanning tool.

This is the main repository for metasm, a free assembler / disassembler / compiler written in ruby

Scans Infrastructure as Code files for security misconfigurations and vulnerabilities using KICS, with Bitbucket Code Insights reporting.

nltk.tokenize.StanfordSegmenter dynamically loads external Java .jar files without verification or sandboxing. If an attacker can supply or replace…

Autonomous white-hat security auditor for AI-driven code review, bug bounty research, exploit construction, and execution-grounded verification.

Mautic < 5.2.3 Authenticated RCE

Checks projects for compromised packages, suspicious files, and import statements.