
wrongsecrets
Vulnerable app with examples showing how to not use secrets

Vulnerable app with examples showing how to not use secrets

One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.

GitHub App to set and enforce security policies

An app that helps you monitor your Kubernetes cluster, debug critical deployments & gives recommendations for standard practices

LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and…

Spring Boot app with log4j 2.14.1 (CVE-2021-44228) — VulnFix agent test target

Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell…

Jenkins plugin for automated mobile app testing via Perfecto cloud, managing secure tunnel connections and app uploads within CI/CD pipelines.

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Run Coding Agents in Sandboxes. Control Them Over HTTP. Supports Claude Code, Codex, OpenCode, and Amp.

Easily create full virtual machines that are sandboxed for development or computer use models.

A doggo that helps look for security issues in your repositories.

CVE-2016-4468

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Static code analysis plugin for Android project. (Checkstyle, PMD)

Cross-platform APK/DEX method finder with call chain tracing, ProGuard deobfuscation, and hidden API detection

Automated scanner that detects Unity runtime injection vulnerability CVE-2025-59489 in Android APKs by extracting Unity version and checking against…

Android CVE-2024-0044, 43093, 23706 zafiyet analizi ve PoC lab ortamı