
VulnReach
Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Audit harness testing whether the CVE-2026-0994 Any-unwrapping recursion bug class affects upb's C core in Ruby and PHP protobuf bindings, with…

Radare2 AI plugin using local or remote LLMs for decompilation, function explanation, vulnerability detection, renaming, and scripted reverse…

RetDec is a retargetable machine-code decompiler based on LLVM.

machofile is a module to parse Mach-O binary files

Find authentication (authn) and authorization (authz) security bugs in web application routes.

Affected versions of this package are vulnerable to Prototype Pollution.

Static analysis scanner for CVE-2020-11023 XSS vulnerabilities in JavaScript. Detects vulnerable jQuery versions and dangerous DOM manipulation…

Simplification of General Mixed Boolean-Arithmetic Expressions: GAMBA

A service that analyzes docker images and scans for vulnerabilities

Efficient Deobfuscation of Linear Mixed Boolean-Arithmetic Expressions

Scanners for Jar files that may be vulnerable to CVE-2021-44228

Applications that are vulnerable to the log4j CVE-2021-44228/45046 issue may be detectable by scanning jar, war, ear, zip files to search for the…

A project security/vulnerability/risk scanning tool

IDA Pro plugin that imports runtime-resolved symbols in .NET Native binaries, parsing SharedLibrary.dll and its PDB to restore missing imports for…