
CVE-2021-44228_scanner-main-Modified-
Scans jar, war, and ear files for the presence of JndiLookup.class to detect applications vulnerable to CVE-2021-44228 (Log4Shell).

Scans jar, war, and ear files for the presence of JndiLookup.class to detect applications vulnerable to CVE-2021-44228 (Log4Shell).

Vulnerable svg-to-png service

Demonstrates CVE-2015-10034 in a vulnerable Java application, including SARIF analysis results from J-TAS Action for educational security testing.

The Python Version of our Not Go-ing Anywhere Vulnerable Application

[Moved to Codeberg] Simple local scanner for vulnerable log4j instances

Educational lab demonstrating CVE-2026-2964, a prototype pollution vulnerability in web-audio-recorder-js leading to RCE. Includes vulnerable and…

Demonstrates a proof-of-concept for CVE-2026-35414, showing a vulnerable and fixed version of SSH principal matching logic to illustrate the flaw.

Proof-of-concept demonstrating command injection in aws-mcp-server via shell=True, with analysis of the vulnerable code and the fix in v1.7.0.

Example Vulnerable application for CVE-2025–57833

Educational lab demonstrating JavaScript expression sandbox escape techniques and patch evolution through multiple vulnerable sandbox versions, with…

Minimal Rust project demonstrating CVE-2021-42574 with compile-time behavior differences between patched and vulnerable rustc versions for…

TROMMEL: Sift Through Embedded Device Files to Identify Potential Vulnerable Indicators

Scanners for Jar files that may be vulnerable to CVE-2021-44228

scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.

Python source code auditing and static analysis on a large scale


Static Analyzer for Starknet smart contracts

Detections for CVE-2021-44228 inside of nested binaries