
jsonorg-fp3
simple application with a (unreachable!) CVE-2022-45688 vulnerability

simple application with a (unreachable!) CVE-2022-45688 vulnerability

[Moved to Codeberg] Simple local scanner for vulnerable log4j instances

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

grep rough audit - source code auditing tool

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

a static analysis tool for finding vulnerabilities in C/C++ source code

Fast Go-based static scanner for detecting sensitive data (API keys, tokens, passwords) in JavaScript files and source code using regex patterns.


CVE-2018-8097 PoC

Technical write-up and PoC for CVE-2026-24009, demonstrating unsafe YAML loading in docling-core and practical mitigation paths.

Standalone Python script to verify if a project is affected by CVE-2025-55182 (React2Shell). Checks package.json dependencies and performs optional…

TinyXML 2.6.2 with fixes for CVE-2021-42260 and CVE-2023-34194

Educational demonstration of CVE-2007-4559 Python tarfile symlink attack with a script showing why os.path.realpath() fails to prevent extraction…

activemq-rce-cve-2023-46604

jee web project with sanitised log4shell (CVE-2021-44228) vulnerability

Java source code generator that creates calling classes for Oracle PL/SQL package procedures, supporting various parameter types and automatic type…