
CVE-2015-10034
Demonstrates CVE-2015-10034 in a vulnerable Java application, including SARIF analysis results from J-TAS Action for educational security testing.

Demonstrates CVE-2015-10034 in a vulnerable Java application, including SARIF analysis results from J-TAS Action for educational security testing.

Reproducible CVE-2015-6748 vulnerability example in jsoup HTML parser, demonstrating XSS prevention bypass and DOM-based parsing flaws for security…

go CVE-2023-24538 patch issue resolver - Kirkstone

Scans code diffs with context to build an impact graph and uses LLMs to find vulnerabilities, supporting multi-repo scans and CI gating with SARIF…

[Moved to Codeberg] Simple local scanner for vulnerable log4j instances

Unpack and deobfuscate VMProtect 2 protected binaries with an emulation-based VM explorer, handler profiler, and experimental LLVM recompiler for…

The Secure Coding Framework


Anteater - CI/CD Gate Check Framework

Static analysis tool for Android APKs that inspects Dalvik bytecode, decodes XML resources, and detects potential issues. Supports binary…

Tool to search secrets in various filetypes.

Using Struts2 and PowerShell to recreate CVE-2017-5638 OGNL Injection vulnerability.

A static analysis tool for securing Go code

Identify hardcoded secrets in static structured text

a javascript static security analysis tool

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…