
noir
Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Behavior-preserving fix for CVE-2025-60876 HTTP header injection in BusyBox wget, with proof-of-concept, percent-encoding patch, and upstream…

Go-based scanner that detects DOMPurify sanitizer bypass (CVE-2026-47423) via logic fingerprinting on minified production JavaScript bundles,…

Static taint analysis platform for Android apps that detects vulnerabilities and compliance issues using customizable rule-based scanning and…

ReactGuard provides framework- and vulnerability-detection tooling for CVE-2025-55182 (React2Shell)

CVE-2025-55182 and CVE-2025-66478

Proof-of-concept exploit for CVE-2025-53964: remote file read/write via malicious XDXF dictionary in GoldenDict 1.5.0/1.5.1, leveraging unsanitized…

Java XML serialization library with a focus on the CVE-2013-7285 deserialization vulnerability, providing source code, binaries, and documentation…

Exploit code and analysis for CVE-2023-26049 targeting Jetty 9.4.31, demonstrating a vulnerability in the web server for security testing and…

Zero shot vulnerability discovery using LLMs

Scans Infrastructure as Code files for security misconfigurations and vulnerabilities using KICS, with Bitbucket Code Insights reporting.

Analyzes and addresses CVE-2023-47108, providing vulnerability assessment and remediation guidance for affected systems.

CVE-2021-46364: YAML Deserialization in Magnolia CMS

Detaped is a Python disassembler and decompiler for Duktape. The intended use is for source code review and analysis in situations where you only…


Amanda 3.5.1 second LPE.

Java-based tool to detect Adobe Flex SWF files vulnerable to CVE-2011-2461, usable as a command-line utility or Burp Suite passive scanner plugin.

Test wether you're exposed to ghost (CVE-2015-0235). All kudos go to Qualys Security