
semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Code-quality and static-analysis platform with quality gates, multi-language scanning, and security-focused rules to detect vulnerabilities and…

Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability

CVE-2026-39259

Proof-of-concept exploit for terminal escape sequence injection via malicious filenames that hides Flawfinder's scan findings; fixed in version…

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata

Educational lab demonstrating CVE-2020-11023 jQuery XSS vulnerability with attack payloads, mitigation techniques (text(), CSP, input validation),…

SyncShield - Browser Extension to Detect Unsafe Rsync Commands (CVE-2018-5764)

Enterprise-grade static code analysis platform with multi-language support, security vulnerability detection, code quality metrics, and DevOps…

Type-safe Java Mustache templating engine with compile-time template validation, static value binding, and extensible escaping for HTML and other…

OWASP ASST (Automated Software Security Toolkit) | A Novel Open Source Web Security Scanner.

Fix prototype pollution vulnerability (CVE-2023-26136) for tough-cookie package

VBScript & VBA source-to-source deobfuscator with partial-evaluation

Bookea-tu-Mesa is vulnerable to SQL Injection

Documentation of CVE-2023-31606: a ReDoS vulnerability in Redcloth gem's sanitize_html function, with root cause analysis, CVSS 7.5 scoring, and…

AWS Serverless Security

Sourcetrail - free and open-source interactive source explorer

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container