
brakeman
A static analysis security vulnerability scanner for Ruby on Rails applications

A static analysis security vulnerability scanner for Ruby on Rails applications

Advisory and proof of concept for CVE-2019-12180, demonstrating arbitrary Groovy code execution in SoapUI and ReadyAPI via malicious project files.

Django application that performs SAST and Malware Analysis for Android APKs

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

The community's most comprehensive, continuously-updated index of research on Large Language Models for software vulnerability detection — papers…

A benchmark for evaluating AI agents on fixing real-world security vulnerabilities.

Proof-of-concept exploit and lab environment for CVE-2026-27495

Log4j 漏洞本地检测脚本。 Scan all java processes on your host to check whether it's affected by log4j2 remote code execution vulnerability (CVE-2021-45046)


Exploit on the default cache of superset by using pickle

Open-source secret scanner in Rust

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

Proof-of-concept emulation and analysis of CVE-2025-1094, a critical PostgreSQL SQL injection vulnerability. Includes Docker-based lab setup, exploit…

SnakeYAML-CVE-2022-1471-POC

Vulnerabilities in the Git node allowed authenticated users with permission to create or modify workflows to execute arbitrary system commands or…

Metasploit module that exploits a WordPress unserialization vulnerability (CVE-2024-31211) in WP_HTML_Token to achieve remote code execution.

Plugin for JADX to integrate MCP server

Static code analysis tool based on Elasticsearch