
jsecret
Fast Go-based static scanner for detecting sensitive data (API keys, tokens, passwords) in JavaScript files and source code using regex patterns.

Fast Go-based static scanner for detecting sensitive data (API keys, tokens, passwords) in JavaScript files and source code using regex patterns.

Technical write-up and PoC for CVE-2026-24009, demonstrating unsafe YAML loading in docling-core and practical mitigation paths.

grep rough audit - source code auditing tool

A simple project to check coverage of Log4J vuln CVE-2021-44228 (and related)

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…

A simple file-based scanner to look for potential AWS access and secret keys in files

SASM - simple crossplatform IDE for NASM, MASM, GAS and FASM assembly languages

TinyXML 2.6.2 with fixes for CVE-2021-42260 and CVE-2023-34194

a static analysis tool for finding vulnerabilities in C/C++ source code

Java source code generator that creates calling classes for Oracle PL/SQL package procedures, supporting various parameter types and automatic type…

Proof-of-Concept (POC) of a simple firewall in Python designed to mitigate the Spring4Shell (CVE-2022-22965) RCE attack by inspecting and blocking…

A simple PoC for WordPress RCE (author priviledge), refer to CVE-2019-8942 and CVE-2019-8943.

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

simple application with a CVE-2022-45688 vulnerability

Standalone Python script to verify if a project is affected by CVE-2025-55182 (React2Shell). Checks package.json dependencies and performs optional…

simple application with a CVE-2022-45688 vulnerability

[Moved to Codeberg] Simple local scanner for vulnerable log4j instances