
CVE-2019-5413-NetBeans-NoJson
Proof-of-concept exploit for CVE-2019-5413, a remote code execution vulnerability in Apache NetBeans. Demonstrates exploitation via crafted XML…

Proof-of-concept exploit for CVE-2019-5413, a remote code execution vulnerability in Apache NetBeans. Demonstrates exploitation via crafted XML…

Proof-of-concept exploit for CVE-2019-5413 targeting NetBeans IDE, demonstrating remote code execution via crafted project files.

Proof-of-concept exploit for CVE-2018-11235, a remote code execution vulnerability in Git submodules. Demonstrates exploitation of malicious…

Wordpress IgniteUp plugin < 3.4.1 allows unauthenticated users to arbitrarily delete files on the webserver possibly causing DoS.

Proof-of-concept exploit for CVE-2022-0219, an XXE vulnerability in Jadx that allows local file disclosure when exporting malicious APK files via the…

PoC code to download files with CVE-2024-32830

Applications that are vulnerable to the log4j CVE-2021-44228/45046 issue may be detectable by scanning jar, war, ear, zip files to search for the…

Scans jar, war, and ear files for the presence of JndiLookup.class to detect applications vulnerable to CVE-2021-44228 (Log4Shell).

Created after the disclosure of CVE-2021-44228. Bash script that detects Log4j occurrences in your projects and systems, allowing you to get insight…

Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and…

A tool written in Go that scans files & directories for the Follina exploit (CVE-2022-30190)

A macOS app to scan Xcode project files for possible security issues.

Detect potentially malicious PHP files

Nasha is a Virtual Machine for .NET files and its runtime was made in C++/CLI

Checks your files for existence of Unicode BIDI characters which can be misused for supply chain attacks. See CVE-2021-42574

Scanners for Jar files that may be vulnerable to CVE-2021-44228

Find, verify, and analyze leaked credentials

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…