
railsgoat
A vulnerable version of Rails that follows the OWASP Top 10

A vulnerable version of Rails that follows the OWASP Top 10

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

CVE-2019-10172 PoC and Possible mitigations

a fast check, if your server could be vulnerable to CVE-2021-44228

Scanners for Jar files that may be vulnerable to CVE-2021-44228

Static Analyzer for Starknet smart contracts

Python source code auditing and static analysis on a large scale

TROMMEL: Sift Through Embedded Device Files to Identify Potential Vulnerable Indicators

The Python Version of our Not Go-ing Anywhere Vulnerable Application

Static analysis scanner for CVE-2020-11023 XSS vulnerabilities in JavaScript. Detects vulnerable jQuery versions and dangerous DOM manipulation…

Bash and PowerShell scripts to scan a local filesystem for Log4j .jar files which could be vulnerable to CVE-2021-44228 aka Log4Shell.

Minimal Rust project demonstrating CVE-2021-42574 with compile-time behavior differences between patched and vulnerable rustc versions for…

Proof-of-concept exploit for CVE-2022-0219, an XXE vulnerability in Jadx that allows local file disclosure when exporting malicious APK files via the…

Synthetic CWE-120 stack buffer overflow variant of CVE-2020-8597 (pppd EAP) as a CodeQL static-analysis target

Scanning tool for identifying local privilege escalation issues in vulnerable MSI installers

Detect and patch vulnerable Apache Commons Text in Java JAR/WAR artifacts; fingerprint classes and scan bytecode for CVE-2022-42889 (Text4Shell) call…

A tool for finding vulnerable libwebp(CVE-2023-4863)

Defensive vulnerability-research project comparing vulnerable and patched Grandstream GXP1600 firmware for CVE-2026-2329, using SquashFS extraction,…