
Awesome-LLMs-for-Vulnerability-Detection
The community's most comprehensive, continuously-updated index of research on Large Language Models for software vulnerability detection — papers…

The community's most comprehensive, continuously-updated index of research on Large Language Models for software vulnerability detection — papers…

Peer-to-peer code collaboration and publishing stack with a secure, decentralized protocol, CLI tool, and network daemon for sovereign code forges.

Given JSON-like content, The JSON Sanitizer converts it to valid JSON.

OWASP Secure Agent Playbook Project

Open-source security gateway & static scanner for AI agents. Enforce role-based access control (RBAC), human-in-the-loop approvals, segregation of…

Claude Skill that audits your projects for RLS misconfigurations, exposed keys, auth bypasses, and storage vulnerabilities. 27 anti-patterns sourced…

CVE-2022-21660

A comprehensive browser extension (.xpi) malware scanner which checks for many common malware tricks like:, credential-stealers obfuscation tactics,…

IDOR + Stored XSS via Broken Object-Level Authorization in JoomGallery

PHP 8.4+ security library (mirror)

Security Advisory: Insufficient Access Controls Allow for Unauthorized Room Deletion (Let's Chat)

Detailed technical analysis of CVE-2026-47777, a high-severity authorization bypass in Mastodon's Featured Collections federation pipeline, including…

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

A security-hardened fork of the abandoned "PostGallery" WordPress plugin. Fixes critical Arbitrary File Upload (CVE-2025-13543) and Guest Access…

A security-patched fork of the legacy ClickFunnels Classic WordPress plugin. Fixes critical Stored XSS vulnerabilities (CVE-2022-4782) while…

authz research - CVE-2026-3306 fix coverage

A security-hardened fork of Crowdsignal Forms. Patches CVE-2025-69015 (Broken Access Control), modernizes for PHP 8.2+, and enforces strict…

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…