
progpilot
PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…

PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

find hardcoded strings from source code

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

Python Command-Line Ghidra Decompiler

VBScript & VBA source-to-source deobfuscator with partial-evaluation

A list of awesome penetration testing tools and resources.

Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

Current development for Call Map takes place at https://github.com/ajylee/call_map. Call Map is a tool for navigating Python call graphs.

The ASN1_STRING_set() function takes an `int` length, make sure the argument is not inadvertently truncated when it is called from asn1_ex_c2i().

Generates five .NET deserialization payload formats for CVE-2026-56158, delivers them over HTTP/SOAP/JSON endpoints, includes mock server, scanner,…

CVE-2026-39259

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

SyncShield - Browser Extension to Detect Unsafe Rsync Commands (CVE-2018-5764)

Shell script to recursively scan folders for Go binaries using insecure pem.Decode function, detecting vulnerable or stripped binaries for…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

OpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm:…