
gradle-static-analysis-plugin
Easy setup of static analysis tools for Android and Java projects.

Easy setup of static analysis tools for Android and Java projects.

NCC Code Navigator

Proof-of-concept exploit for terminal escape sequence injection via malicious filenames that hides Flawfinder's scan findings; fixed in version…

Fix prototype pollution vulnerability (CVE-2023-26136) for tough-cookie package

Java utility library with patched CVE-2022-4244 vulnerability, providing common helper classes for I/O, reflection, and CLI argument parsing in…

Whalescan is a vulnerability scanner for Windows containers, which performs several benchmark checks, as well as checking for CVEs/vulnerable…

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

CVE-2026-39259

Static analysis scanner for infrastructure-as-code that detects security vulnerabilities, compliance violations, and misconfigurations across…

SAST CLI for scanning Java, JavaScript, and .NET applications plus AWS Lambda functions, detecting code vulnerabilities and over-permissive IAM…

BianryNinja plugin for identifying vulnerabilities in decompiled binaries with both programmatic scans and LLM support.

Policy-governed LLMSecOps framework providing AST-based SAST, secret scanning, supply-chain and multi-cloud CSPM checks, AI-BoM generation, and CI/CD…

Enterprise-grade static code analysis platform with multi-language support, security vulnerability detection, code quality metrics, and DevOps…

MCP server plugin for JEB Pro that enables AI-assisted decompilation, method/field inspection, and automated renaming during APK reverse engineering.

Static code analysis plugin for Android project. (Checkstyle, PMD)

OWASP ASST (Automated Software Security Toolkit) | A Novel Open Source Web Security Scanner.

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata