
alibi
Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

Offline Java tool that scans application jars to determine exposure to 14 Netty codec-http CVEs, identifying the exact patched version…

Scans code diffs with context to build an impact graph and uses LLMs to find vulnerabilities, supporting multi-repo scans and CI gating with SARIF…

Upgrade to Apache 2.4.67 to fix CVE-2026-23918 vulneribility

This is a proactive tool for security auditing. For your GitHub repository, you’ll want a description that highlights its safety (non-intrusive) and…

Information about CVE-2026-27825 & CVE-2026-27826 discovered by Pluto Security and a bash script for identifying vulnerable mcp-atlassian instances…

Read-only checker for CVE-2026-43284 / CVE-2026-43500 (Dirty Frag) Linux kernel local-root vulns

Automated detection and remediation of ServiceNow UI Macro vulnerabilities (CVE-2025-11449, CVE-2025-11450) by encoding sysparm_ parameters to…

Patch: Template injection RCE (Atlassian Confluence)

Patch: Privilege escalation via web UI (Cisco IOS XE)

A security scanner for your LLM agentic workflows

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

Script to audit GitHub Action Workflow files for potential vulnerabilities.

LLM powered fuzzing via OSS-Fuzz.

PoC for CVE-2026-22018, a critical Jenkins Pipeline Shared Library RCE via Groovy @Grab, demonstrating supply-chain code injection and mitigation…

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

sprint encode (plan text) get enc password