
zairo
Scans code diffs with context to build an impact graph and uses LLMs to find vulnerabilities, supporting multi-repo scans and CI gating with SARIF…

Scans code diffs with context to build an impact graph and uses LLMs to find vulnerabilities, supporting multi-repo scans and CI gating with SARIF…

Collection of Solidity snippets and Foundry scripts for smart contract security audits

Offline checker for Thymeleaf CVE-2026-40477 / CVE-2026-41901 — tells you which of the two CVSS 9.0 SSTI flaws you are exposed to, and whether your…

Provenance-aware Linux kernel vulnerability research harness used in the investigation of CVE-2026-53075

Evidence-driven Linux kernel vulnerability research harness used in the investigation of CVE-2026-31720

Secure, fast, and portable C90 implementation of ML-KEM / FIPS 203

Proof-of-concept demonstrating command injection in aws-mcp-server via shell=True, with analysis of the vulnerable code and the fix in v1.7.0.

A scanner and testter of the CVE-2025-11001 of 7-zip

Created after the disclosure of CVE-2021-44228. Bash script that detects Log4j occurrences in your projects and systems, allowing you to get insight…

Demonstrates a proof-of-concept for CVE-2026-35414, showing a vulnerable and fixed version of SSH principal matching logic to illustrate the flaw.

All stages of exploring the polkit CVE-2021-4034 using codeql

Educational demo of three Claude Code vulnerabilities (hooks bypass, MCP injection, API key exfiltration) with attacker server, MITM proxy, and…

Analyzes a specific CVE in WeChat OAuth handler, identifying unbounded HTTP response reads leading to denial of service, with remediation guidance.

Detailed analysis of CVE-2021-22569, a high-severity denial-of-service vulnerability in protobuf-java, including affected versions, patched versions,…

Collection of Semgrep rules for static code analysis, detecting security vulnerabilities, and enforcing secure coding practices across multiple…

The Python Version of our Not Go-ing Anywhere Vulnerable Application

Generate Objective-C headers from Mach-O files.

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…