
DakshSCRA
Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

A list of awesome penetration testing tools and resources.

Research-only AI watermark robustness toolkit: local reverse proxy strips C2PA/EXIF/XMP, Unicode, image/audio stego, OOXML/PDF metadata, and scans…

Bookea-tu-Mesa is vulnerable to SQL Injection

The Secure Coding Practices Quick-reference Guide from OWASP

Curated database of Apple internal artifacts (entitlements, frameworks, device versions) with API, CLI, and WebUI for iOS/macOS security research and…

Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata

Fix prototype pollution vulnerability (CVE-2023-26136) for tough-cookie package

Sourcetrail - free and open-source interactive source explorer

A collection of my Semgrep rules to facilitate vulnerability research.

OWASP ASST (Automated Software Security Toolkit) | A Novel Open Source Web Security Scanner.

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

Proof-of-concept exploit for terminal escape sequence injection via malicious filenames that hides Flawfinder's scan findings; fixed in version…

A collection of smart contract vulnerabilities along with prevention methods