
sec-af
AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of…

Isolated JavaScript sandbox for Node.js that runs untrusted code with restricted access to built-in modules and host resources via Proxy-based…

Orbit Tracer Security Agent for intelligent security remediation. Traces vulnerability blast radius using Orbit's knowledge graph, scores risk,…

100% Free & Open Source • Privacy-First Security Scanning and AI Code Review CLI


CVE-2024-4367 mitigation for Odoo 14.0

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

Coverage-based fuzzer for python applications

This is a showcase how the Log4J vulnerability (CVE-2021-44228) could be explored. This code is safe to run, but understand what it does and how it…

PHPMailer < 5.2.18 Remote Code Execution

Demo app showing how the Rails CVE-2013-5664 vulnerability works.