
smart-contract-vulnerabilities
A collection of smart contract vulnerabilities along with prevention methods

A collection of smart contract vulnerabilities along with prevention methods

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

A collection of my Semgrep rules to facilitate vulnerability research.

Tool for reverse engineering of Angular applications

Static analysis tool for detecting ReDoS (Regular Expression Denial of Service) vulnerabilities in JavaScript and Scala codebases, providing…

Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)

👮 👊 RegEx Denial of Service (ReDos) Scanner

A list of awesome penetration testing tools and resources.

Curated weggli queries for static analysis of C/C++ code to identify dangerous functions, stack issues, and malloc overflow vulnerabilities.

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

Synthetic CWE-120 stack buffer overflow variant of CVE-2020-8597 (pppd EAP) as a CodeQL static-analysis target

Documentation of CVE-2023-31606: a ReDoS vulnerability in Redcloth gem's sanitize_html function, with root cause analysis, CVSS 7.5 scoring, and…

A security-hardened fork of "Simply Show Hooks". Replaces the compromised original (CVE-2024-6297) and patches unlisted Cross-Site Scripting (XSS)…

Easy setup of static analysis tools for Android and Java projects.

Code-quality and static-analysis platform with quality gates, multi-language scanning, and security-focused rules to detect vulnerabilities and…

KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best…

Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your…

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.