
semgrep-rules
Collection of Semgrep rules for static code analysis, detecting security vulnerabilities, and enforcing secure coding practices across multiple…

Collection of Semgrep rules for static code analysis, detecting security vulnerabilities, and enforcing secure coding practices across multiple…

Reference implementation of Bean Validation 2.0 (JSR-380) providing annotation-driven metadata model and API for JavaBean and method validation with…

A request parameter filter solution for Struts 1 CVE-2014-0114 based on the work of Alvaro Munoz and the HP Fortify team

Spring Web 5.x with `org.springframework.remoting` package removed, to fix CVE-2016-1000027.

Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and…

Fastest filesystem scanner for log4shell (CVE-2021-44228, CVE-2021-45046) and other vulnerable (CVE-2017-5645, CVE-2019-17571, CVE-2022-23305,…

Java library for fast, configurable HTML sanitization from untrusted sources. Uses policy-driven scanning to remove malicious JavaScript and CSS,…

This repository contains potential security patches for the Magento APSB22-48 and CVE-2022-35698 security vulnerability

Fixes CVE-2021-44228 in log4j by patching JndiLookup class

Discover Log4Shell vulnerability [CVE-2021-44832]

Simple tool for scanning entire directories for attempts of CVE-2021-44228

Module for PrestaShop 1.7.X to fix CVE-2023-28447 vulnerability (Smarty XSS)

A fix for CVE-2019-11358 (prototype pollution in jquery)

Secure fork of Startklar Elementor Addons. Patched CVE-2024-5153 & File Upload vulnerabilities.

Rapidly scan filesystems for Java programs potentially vulnerable to Log4Shell (CVE-2021-44228) or "that Log4j JNDI exploit" by inspecting the class…

Electronegativity is a tool to identify misconfigurations and security anti-patterns in Electron applications.

Checks your files for existence of Unicode BIDI characters which can be misused for supply chain attacks. See CVE-2021-42574