
wrongsecrets
Vulnerable app with examples showing how to not use secrets

Vulnerable app with examples showing how to not use secrets

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

GitHub App to set and enforce security policies

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Easily create full virtual machines that are sandboxed for development or computer use models.

A doggo that helps look for security issues in your repositories.

Run Coding Agents in Sandboxes. Control Them Over HTTP. Supports Claude Code, Codex, OpenCode, and Amp.

Android CVE-2024-0044, 43093, 23706 zafiyet analizi ve PoC lab ortamı

Spring Boot app with log4j 2.14.1 (CVE-2021-44228) — VulnFix agent test target

Cross-platform APK/DEX method finder with call chain tracing, ProGuard deobfuscation, and hidden API detection

One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.

Automated scanner that detects Unity runtime injection vulnerability CVE-2025-59489 in Android APKs by extracting Unity version and checking against…

Jenkins plugin for automated mobile app testing via Perfecto cloud, managing secure tunnel connections and app uploads within CI/CD pipelines.

Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell…

An app that helps you monitor your Kubernetes cluster, debug critical deployments & gives recommendations for standard practices

LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and…

Easy setup of static analysis tools for Android and Java projects.

CVE-2016-4468