
CVE-2022-2869-detector
CodeQL detector for CVE-2022-2869 root cause (CWE-191 unsigned underflow) using control-flow/range analysis to identify vulnerable patterns without…

CodeQL detector for CVE-2022-2869 root cause (CWE-191 unsigned underflow) using control-flow/range analysis to identify vulnerable patterns without…

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Pluggable linting tool to prevent committing credential.

Found a 0-Day in Ghidra: Shared Project File Became a Code Execution Vector

Reproducer for CVE-2026-43867 — Apache Camel camel-pqc AwsSecretsManagerKeyLifecycleManager unsafe key-metadata deserialization (RCE)

Reproducer for CVE-2026-33454: Apache Camel camel-mail header injection to RCE via camel-exec

Externalize Java application access to protected resources as log messages.

Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability

Orbit Tracer Security Agent for intelligent security remediation. Traces vulnerability blast radius using Orbit's knowledge graph, scores risk,…

Python tool for analyzing CVE-2018-16763 in FUEL CMS with cleaner response parsing and interactive vulnerability checking.

Using Struts2 and PowerShell to recreate CVE-2017-5638 OGNL Injection vulnerability.

Modular security toolkit for autonomous agents providing static analysis, configuration auditing, runtime monitoring, and supply chain verification…

Automated secret and leak detection scanner for GitHub and paste sites, with heuristic filtering, IOL enrichment via Shhgit/TruffleHog, and ELK-based…

The Secure Coding Practices Quick-reference Guide from OWASP

Reproduction environment for CVE-2025-13465, demonstrating a vulnerability in Next.js applications using Lodash. Provides a minimal setup to test and…

Proof-of-concept exploit for CVE-2026-22686, demonstrating remote code execution in Node.js ESM sandboxes via process.getBuiltinModule to bypass…

Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…