
trivy-action
Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across…

Educational exploit demo for CVE-2018-1263 (phpMyAdmin RCE/LFI). Includes vulnerable environment setup via Docker and step-by-step attack walkthrough…

Reproducible example demonstrating CVE-2024-26308 vulnerability detection during Docker builds, with Maven dependency tree analysis and remediation…

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Detects CVE-2025-55182 RCE in React Server Components by scanning npm/pnpm/yarn lockfiles, Docker images, SBOMs, and live URLs. Includes auto-fix,…

Nuclio Dashboard (NOP mode) accepts unauthenticated POST /api/functions. The spec.handler field isn't path-validated, so…


Scans GitHub Actions CI/CD workflows for security vulnerabilities, indexes findings into a Neo4j graph database, and provides a query library for…

Django application that performs SAST and Malware Analysis for Android APKs

Top-level repository for LFI: Practical, Efficient, and Secure Software-based Sandboxing

Enhanced fuzzing for tmux using OSS-Fuzz. Includes custom `cmd-fuzzer` and `argument-fuzzer` harnesses for improved code coverage and a PoC for…

Macro-header for compile-time C obfuscation (tcc, win x86/x64)

The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

agent runtime security - zero trust, zero setup, zero latency.

Open-source, cross-platform, multi-purpose security auditing tool

Open-source secret scanner in Rust

A Python-based static patch analysis tool for studying the root cause and remediation of CVE-2021-41773 (Apache HTTP Server Path Traversal) by…