
magika
Fast and accurate AI powered file content types detection

Fast and accurate AI powered file content types detection

A collection of my Semgrep rules to facilitate vulnerability research.

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain

CVE-2022-3653 just the c++ component in Vulkan for later study

Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

A wrapper around grep, to help you grep for things

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Detection script for cve-2021-23358

This project is just to show Apache Log4j2 Vulnerability - aka CVE-2021-44228

PoC for CVE-2020-28032 (It's just a POP chain in WordPress < 5.5.2 for exploiting PHP Object Injection)



Proof-of-concept exploit for CVE-2018-6574 targeting a Go web server vulnerability. Demonstrates remote code execution via crafted HTTP requests.

Just a normal flask web app to understand win32api with code snippets and references.