
CVE-2021-44228
Professional Service scripts to aid in the identification of affected Java applications in TeamServer

Professional Service scripts to aid in the identification of affected Java applications in TeamServer

I have created AegisJava, a tool to fix (detect and mitigate) CVE-2025-30749.

CVE-2016-4468

Open-source Interactive Application Security Testing (IAST) tool that passively instruments Java applications to detect vulnerabilities and…


A static analyzer for Java, C, C++, and Objective-C

PacBot (Policy as Code Bot)

Tree-sitter based static vulnerability scanner with pattern matching and taint-flow analysis for multi-language source code. Outputs findings as…

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

CLI and MCP server that checks package versions for known vulnerabilities across 14+ ecosystems including npm, PyPI, crates.io, Go modules, and…

Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.

SAST CLI for scanning Java, JavaScript, and .NET applications plus AWS Lambda functions, detecting code vulnerabilities and over-permissive IAM…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.