
Vulnvault
Developer-focused knowledge base of application security vulnerabilities with insecure vs secure code examples, prevention guidance, and OWASP/CWE…

Developer-focused knowledge base of application security vulnerabilities with insecure vs secure code examples, prevention guidance, and OWASP/CWE…

Community Cryptography Specification Project

Public security advisories and PoCs for vulnerabilities discovered in open-source web software, with root-cause analysis, CVE references,…

Agent skills for firmware extraction, static analysis, Ghidra reverse engineering, emulation, and security reporting, packaged for Claude Code and…

Free security-baseline rule for Claude Code, Codex, and Cursor: treats MCP tool descriptions as untrusted input (OWASP MCP Top 10 MCP03,…

Collection of Solidity snippets and Foundry scripts for smart contract security audits

Static XML fixtures for authorized bug bounty testing of XML parser behaviour (CVE-2026-45071).

WooCommerce plugin: safe formula-based product pricing, closing CVE-2026-4001's eval()-based RCE

Benchmark task for reimplementing a masked path-resolution fix in Jupyter Server, with functional and hidden security tests to evaluate…

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

List of mixed boolean-arithmetic resources

Curated collection of LLVM security resources covering binary lifting, code obfuscation, static analysis, symbolic execution, sanitizers, and…

Twitter vulnerable snippets

A list of Blockchain Security audit companies, solo auditors and location of public audits.

Mind-Maps of Several Things

Demystifying Exploitable Bugs in Smart Contracts

The community's most comprehensive, continuously-updated index of research on Large Language Models for software vulnerability detection — papers…