
horusec
Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

0-day malware detection for binaries, source & scripts (that doesn't suck)

PoC reproducer for CVE-2026-55994 (Apache Camel camel-iggy): the consumer copies an Iggy message's user-headers onto the Exchange unfiltered, so an…

CVE-2026-52887 — NocoBase SQL injection -> PostgreSQL-superuser RCE (myInAppChannels:list filter, CVSS 10.0). Author PoC + source analysis + docker…

Benchmark measuring AI models' ability to detect vulnerabilities in source code via real bug bounty cases with balanced recall and false-positive…

Introduction to CVE-2023-6933 Vulnerability

Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)

Proof-of-concept (PoC) exploit for JSONPath-plus vulnerability

Proof-of-concept exploit for CVE-2023-4634, a remote code execution vulnerability in the WordPress Media Library Assistant plugin. Includes a…

A static analysis tool for securing Go code

Proof-of-concept exploit for CVE-2023-32571 demonstrating Dynamic Linq injection to achieve remote code execution, with a Docker-based lab…

Proof of concept for CVE-2022-23614 (command injection in Twig)

Proof-of-concept exploit for CVE-2023-36664, a Ghostscript command injection vulnerability. Includes Docker lab environment, detailed analysis of…

Proof of concept for XXE in Ktor (CVE-2023-45612)

Static code analysis tool based on Elasticsearch

The community's most comprehensive, continuously-updated index of research on Large Language Models for software vulnerability detection — papers…

Kurukshetra - A framework for teaching secure coding by means of interactive problem solving.