
codeql
CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Vulnerability Patterns Detector for C# and VB.NET

A static code analysis for WordPress (and PHP)

Indexes C/C++ build artifacts into a queryable whole-program database, exposing AST, token, and IR-level APIs for code auditing and vulnerability…

Static PHP code scanner that detects SQL injection, XSS, SSRF, LFI, command injection, insecure deserialization, and other web vulnerabilities in…

Automated static code analysis framework integrated with SonarQube for early vulnerability detection in source code by scanning Git repositories…

Command-line static analysis scanner that detects critical vulnerabilities in PHP and YAML source code using custom semgrep rules, with Jira and…

Static code analysis scanner for WordPress plugins and themes. Detects vulnerabilities like XSS and SQL injection via modular, extensible…

Apache Log4j 1.2.X存在反序列化远程代码执行漏洞

Apache ShardingSphere UI YAML解析远程代码执行漏洞

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…


CVE-2019-17564:Apache Dubbo反序列化漏洞

Proof-of-concept exploit for CVE-2018-20718, a PHP object injection vulnerability in Pydio before 8.2.1 enabling unauthenticated remote code…

Python exploit script for CVE-2021-23369, a Remote Code Execution vulnerability in Handlebars template engine versions before 4.7.7. Accepts a target…

bypass all stages of the password reset flow

Proof-of-concept and analysis for CVE-2020-1947, a YAML deserialization remote code execution vulnerability in Apache ShardingSphere UI, including…

Proof-of-concept exploit for CVE-2024-28397, a sandbox escape in js2py allowing remote code execution via crafted JavaScript, with a dynamic patch…