
semgrep-rules
Collection of Semgrep rules for static code analysis, detecting security vulnerabilities, and enforcing secure coding practices across multiple…

Collection of Semgrep rules for static code analysis, detecting security vulnerabilities, and enforcing secure coding practices across multiple…

Secure fork of Startklar Elementor Addons. Patched CVE-2024-5153 & File Upload vulnerabilities.

Java library for fast, configurable HTML sanitization from untrusted sources. Uses policy-driven scanning to remove malicious JavaScript and CSS,…

Electronegativity is a tool to identify misconfigurations and security anti-patterns in Electron applications.

Reference implementation of Bean Validation 2.0 (JSR-380) providing annotation-driven metadata model and API for JavaBean and method validation with…

Spring Web 5.x with `org.springframework.remoting` package removed, to fix CVE-2016-1000027.

Discover Log4Shell vulnerability [CVE-2021-44832]

Fastest filesystem scanner for log4shell (CVE-2021-44228, CVE-2021-45046) and other vulnerable (CVE-2017-5645, CVE-2019-17571, CVE-2022-23305,…

This repository contains potential security patches for the Magento APSB22-48 and CVE-2022-35698 security vulnerability

Module for PrestaShop 1.7.X to fix CVE-2023-28447 vulnerability (Smarty XSS)

Checks your files for existence of Unicode BIDI characters which can be misused for supply chain attacks. See CVE-2021-42574

Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and…

Rapidly scan filesystems for Java programs potentially vulnerable to Log4Shell (CVE-2021-44228) or "that Log4j JNDI exploit" by inspecting the class…

Simple tool for scanning entire directories for attempts of CVE-2021-44228

Fixes CVE-2021-44228 in log4j by patching JndiLookup class

A fix for CVE-2019-11358 (prototype pollution in jquery)

A request parameter filter solution for Struts 1 CVE-2014-0114 based on the work of Alvaro Munoz and the HP Fortify team