
honeyslop
Code canaries to quickly triage hallucinated ('slop') vulnerability reports

Code canaries to quickly triage hallucinated ('slop') vulnerability reports

Agent-powered vulnerability scanner for large-scale codebases. Uses LLMs to find hard-to-detect security issues via regex matchers and AI…

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses MultipartFile.transferTo() to…

Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass…

Cursor plugin for Hono v4 (TypeScript edge web framework). 59 LLM regressions with BAD/CORRECT pairs. Pinned to hono ^4.12.19 (>= 4.9.7 for…

Senior-CSO security audit skill for vibe-coded apps. 22-check audit anchored to real 2026 incidents (Moltbook, Lovable CVE-2025-48757). Drop-in…

MapPress Maps Pro < 2.53.9 - Remote Code Execution (RCE) due to Incorrect Access Control in AJAX Actions

Proof-of-Concept (POC) of a simple firewall in Python designed to mitigate the Spring4Shell (CVE-2022-22965) RCE attack by inspecting and blocking…

nameko Arbitrary code execution due to YAML deserialization

This is to patch CVE-2022-30190. Use at your own risk.

Plugin to fix security vulnerability CVE-2023-40626 in Joomla 3.10.12

Scans GitHub Actions CI/CD workflows for security vulnerabilities, indexes findings into a Neo4j graph database, and provides a query library for…

A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.

Discover input surfaces and security issues in compiled .NET assemblies — without running them.

ngxray — nginx config security scanner

Detect and fix log4j log4shell vulnerability (CVE-2021-44228)

This repository provides a workaround preventing exploitation of SECURITY-3430 / CVE-2024-43044