
json-sanitizer
Given JSON-like content, The JSON Sanitizer converts it to valid JSON.

Given JSON-like content, The JSON Sanitizer converts it to valid JSON.

Static PHP code scanner that detects SQL injection, XSS, SSRF, LFI, command injection, insecure deserialization, and other web vulnerabilities in…

Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

CVE-2022-21660

Go package that checks if RSA keys are vulnerable to ROCA / CVE-2017-15361

IDOR + Stored XSS via Broken Object-Level Authorization in JoomGallery

PHP 8.4+ security library (mirror)

Detailed technical analysis of CVE-2026-47777, a high-severity authorization bypass in Mastodon's Featured Collections federation pipeline, including…

This repository provides a comprehensive security remediation of denial-of-service and allocation of resources without limits or throttling security…

A security-hardened fork of the abandoned "PostGallery" WordPress plugin. Fixes critical Arbitrary File Upload (CVE-2025-13543) and Guest Access…

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

authz research - CVE-2026-3306 fix coverage

Java security library providing contextual encoders and sanitizers to automatically remediate vulnerabilities like XSS, path traversal, and command…

Java library that converts malformed JSON-like content into standards-compliant, safe JSON, preventing code injection and ensuring embeddability in…

OpenSSL 1.0.1g source code snapshot, providing SSL/TLS and general-purpose cryptography library with ciphers, digests, and X.509 certificate handling.

Fork of lodash.template with CVE-2021-23337 fix (command injection via variable option)

Generic wiki/HTML rendering system that converts textual input between syntaxes (wiki, HTML, XHTML). This repository contains a patched version…

CVE-2025-27607 fix