
Bughound
Static code analysis tool based on Elasticsearch

Static code analysis tool based on Elasticsearch

APKinspector is a powerful GUI tool for analysts to analyze the Android applications.

Fast and accurate AI powered file content types detection

Use regular expressions to get sensitive information from a given repository (GitHub, pip or npm).

Created after the disclosure of CVE-2021-44228. Bash script that detects Log4j occurrences in your projects and systems, allowing you to get insight…

Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and…

PHPMailer < 5.2.18 Remote Code Execution Exploit

Proof-of-concept exploit for CVE-2024-22411 targeting the Avo admin panel. Demonstrates vulnerability exploitation in Ruby-based web applications.

Ruby-based exploit for CVE-2020-15169, demonstrating a specific web application vulnerability with proof-of-concept code for security testing and…

Binary code coverage visualizer plugin for Ghidra

Pre-install security for AI agents, npm packages, and MCP servers. Zero-dep local static analysis; normal scans never execute package code.

Remote command execution in Golang go get command allows an attacker to gain code execution on a system by installing a malicious library.

Scan codebases for quantum-vulnerable cryptography. Detect RSA, ECDSA, Ed25519, ECDH before Q-Day. CycloneDX CBOM + SARIF output.

Reproducible example demonstrating CVE-2024-26308 vulnerability detection during Docker builds, with Maven dependency tree analysis and remediation…

Are you get Tanstack Supply chain attack attack of 5/11? CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx

CVE-2018-6574 POC : golang 'go get' remote command execution during source code build

Proof-of-concept exploit for CVE-2018-6574, a remote code execution vulnerability in Go's 'go get' command, demonstrating exploitation via malicious…

Proof-of-concept exploit for CVE-2018-6574, a remote code execution vulnerability in Go's 'go get' command. Demonstrates exploitation via malicious…