
DepFuzzer
Scans project dependencies for dependency confusion vulnerabilities and checks package owner email takeover risks across multiple registries (npm,…

Scans project dependencies for dependency confusion vulnerabilities and checks package owner email takeover risks across multiple registries (npm,…

A tool to capture all the git secrets by leveraging multiple open source git searching tools

Patched version of the Expat XML parser library addressing multiple CVEs (CVE-2022-22822 through CVE-2022-22827) for AOSP 10 r33, providing…

CVE-2026-5718: Unauthenticated File Upload To RCE in DnD Upload CF7 Plugin

Obfuscates PowerShell and JavaScript scripts using tree-sitter-based parsing with multiple configurable impostor profiles for stealth, size, and…

🔎 Help find Trojan Source vulnerability in code 👀 . Useful for code review in project with multiple collaborators (CI/CD)

Ensemble framework for software vulnerability detection and repair using multiple large language models, with consensus analysis and evaluation tools…

RCE exploit toolkit for CVE-2025-55182 and CVE-2025-66478 in React Server Components. Includes multiple exploit variants, detection scripts, a…

Exploit for CVE-2022-25174 in Jenkins Pipeline Shared Libraries plugin, demonstrating code injection via crafted library definitions for security…

Collection of Semgrep rules for static code analysis, detecting security vulnerabilities, and enforcing secure coding practices across multiple…

Modular framework to detect and prevent dependency confusion attacks by analyzing package manifests across multiple sources and package management…

Scalable assembly analysis platform for indexing, clone search, and executable classification using static, dynamic, and machine-learning techniques…

Curated Semgrep rule repository for GitLab SAST, providing static analysis patterns to detect security vulnerabilities across multiple programming…

Proof-of-concept exploit for CVE-2025-55182, demonstrating remote code execution via prototype chain vulnerability in React Server Components.…

Mitigated version for CVE-2016-1000027 spring web.

Proof-of-concept exploit for CVE-2018-7211 targeting iDashboards 9.6b. Python script for encrypting/decrypting strings to demonstrate the…

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

Advisory for textract ⌯⌲ 15 000 weekly downloads