
CVE-2025-55182
Proof-of-Concept for CVE-2025-55182, a critical unauthenticated RCE in React Server Components.

Proof-of-Concept for CVE-2025-55182, a critical unauthenticated RCE in React Server Components.

A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using…

Tool for reverse engineering of Angular applications

Collection of Semgrep rules for static code analysis, detecting security vulnerabilities, and enforcing secure coding practices across multiple…

ATrace is a tool for tracing execution of binaries on Windows.

Vba2Graph - Generate call graphs from VBA code, for easier analysis of malicious documents.

Command-line tool for fast searching of GitHub repositories, users, and commits to gather open-source intelligence and code-related information.

Proof of Concept Exploit for PrimeFaces 5.x EL Injection (CVE-2017-1000486)

Demonstration of CVE-2022-22947 exploit for Spring Cloud Gateway, providing a proof-of-concept for security testing and vulnerability analysis.

UnauthScout is an OSINT (Open Source Intelligence) tool developed in Bash for passive exploration of assets on version control platforms (GitLab and…

Technical writeup and Proof of Concept (PoC) for CVE-2026-11417: OS Command Injection / Remote Code Execution (RCE) in AWS CDK's NodejsFunction.

Maven-based demonstration of CVE-2023-33246 mitigation for Apache RocketMQ, featuring attack testing and enhanced parameter validation to prevent…

Go-based proof-of-concept exploit for CVE-2018-6574, demonstrating directory traversal in Go's net/http package for security testing and…

Applications that are vulnerable to the log4j CVE-2021-44228/45046 issue may be detectable by scanning jar, war, ear, zip files to search for the…

Scans jar, war, and ear files for the presence of JndiLookup.class to detect applications vulnerable to CVE-2021-44228 (Log4Shell).

Source code for the Binaries of OWASP WrongSecrets

Curated weggli queries for static analysis of C/C++ code to identify dangerous functions, stack issues, and malloc overflow vulnerabilities.