
Creosote
Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

Automated static code analysis framework integrated with SonarQube for early vulnerability detection in source code by scanning Git repositories…

client-side prototype pullution vulnerability scanner

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…

Vulnerability Assessment Scanner with Report Generation

Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability

Proof-of-concept exploit and technical advisory for an Admin+ arbitrary file upload to remote code execution vulnerability in Everest Toolkit…

PHP script to detect CVE-2015-6835 (session deserialization vulnerability) by analyzing source code for unsafe unserialize() calls in session…

Documentation of CVE-2023-31606: a ReDoS vulnerability in Redcloth gem's sanitize_html function, with root cause analysis, CVSS 7.5 scoring, and…

Fix prototype pollution vulnerability (CVE-2023-26136) for tough-cookie package

Java utility library with patched CVE-2022-4244 vulnerability, providing common helper classes for I/O, reflection, and CLI argument parsing in…

Comprehensive Java vulnerability lab with vulnerable and fixed code, attack scenarios, source/sink audit notes, and secure coding guidance for…

CVE-2026-49268 — Analysis and Remediation of an LDAP Injection Authentication Bypass Vulnerability

Web-based Source Code Vulnerability Scanner

Generates five .NET deserialization payload formats for CVE-2026-56158, delivers them over HTTP/SOAP/JSON endpoints, includes mock server, scanner,…

Bookea-tu-Mesa is vulnerable to SQL Injection

Minimal security backport for CVE-2026-8726 in georgringer/news 8.6.0