
static-analysis
Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

Research-only AI watermark robustness toolkit: local reverse proxy strips C2PA/EXIF/XMP, Unicode, image/audio stego, OOXML/PDF metadata, and scans…

A list of awesome penetration testing tools and resources.

A collection of smart contract vulnerabilities along with prevention methods

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

Curated database of Apple internal artifacts (entitlements, frameworks, device versions) with API, CLI, and WebUI for iOS/macOS security research and…

Curated weggli queries for static analysis of C/C++ code to identify dangerous functions, stack issues, and malloc overflow vulnerabilities.

Clickbait. The CVE is AI slop.

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata

A collection of my Semgrep rules to facilitate vulnerability research.

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

Bookea-tu-Mesa is vulnerable to SQL Injection

Type-safe Java Mustache templating engine with compile-time template validation, static value binding, and extensible escaping for HTML and other…

SyncShield - Browser Extension to Detect Unsafe Rsync Commands (CVE-2018-5764)

Fix prototype pollution vulnerability (CVE-2023-26136) for tough-cookie package

CVE-2026-39259

Documentation of CVE-2023-31606: a ReDoS vulnerability in Redcloth gem's sanitize_html function, with root cause analysis, CVSS 7.5 scoring, and…

The Secure Coding Practices Quick-reference Guide from OWASP