
exploit-CVE-2016-10033
PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

MCP server plugin for JEB Pro that enables AI-assisted decompilation, method/field inspection, and automated renaming during APK reverse engineering.

A static code analysis for WordPress (and PHP)

VBScript & VBA source-to-source deobfuscator with partial-evaluation

A variant analysis and visualisation tool that scans codebases for similar vulnerabilities

The Secure Coding Practices Quick-reference Guide from OWASP

Current development for Call Map takes place at https://github.com/ajylee/call_map. Call Map is a tool for navigating Python call graphs.

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool

Research-only AI watermark robustness toolkit: local reverse proxy strips C2PA/EXIF/XMP, Unicode, image/audio stego, OOXML/PDF metadata, and scans…

CVE-2026-39259

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

Type-safe Java Mustache templating engine with compile-time template validation, static value binding, and extensible escaping for HTML and other…

Easy setup of static analysis tools for Android and Java projects.