
cfn_nag
Linting tool for CloudFormation templates

Linting tool for CloudFormation templates

SAST CLI for scanning Java, JavaScript, and .NET applications plus AWS Lambda functions, detecting code vulnerabilities and over-permissive IAM…

Code-quality and static-analysis platform with quality gates, multi-language scanning, and security-focused rules to detect vulnerabilities and…

Open-source, cross-platform, multi-purpose security auditing tool

A static analysis tool for securing Go code

Enterprise-grade static code analysis platform with multi-language support, security vulnerability detection, code quality metrics, and DevOps…

MCP server plugin for JEB Pro that enables AI-assisted decompilation, method/field inspection, and automated renaming during APK reverse engineering.

OWASP ASST (Automated Software Security Toolkit) | A Novel Open Source Web Security Scanner.

Static code analysis plugin for Android project. (Checkstyle, PMD)

Proof-of-concept exploit for terminal escape sequence injection via malicious filenames that hides Flawfinder's scan findings; fixed in version…

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata

SyncShield - Browser Extension to Detect Unsafe Rsync Commands (CVE-2018-5764)

Educational lab demonstrating CVE-2020-11023 jQuery XSS vulnerability with attack payloads, mitigation techniques (text(), CSP, input validation),…

Bookea-tu-Mesa is vulnerable to SQL Injection

Fix prototype pollution vulnerability (CVE-2023-26136) for tough-cookie package

Type-safe Java Mustache templating engine with compile-time template validation, static value binding, and extensible escaping for HTML and other…

AI-powered bug bounty hunting toolkit that works with or without subscription.

Easy setup of static analysis tools for Android and Java projects.