
VulnReach
Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.
code-analysisdevsecopsdynamic-analysis-sandboxing+5

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Educational PoC + lab for CVE-2026-63030 + CVE-2026-60137: pre-auth SQLi in WordPress core via REST batch-route confusion

Find authentication (authn) and authorization (authz) security bugs in web application routes.

Link sources to sinks in C# applications.