
matt.net
Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool

Matt.Net is a simple GUI wrapper around Microsoft's CAT.NET Code Auditing Tool

Policy-governed LLMSecOps framework providing AST-based SAST, secret scanning, supply-chain and multi-cloud CSPM checks, AI-BoM generation, and CI/CD…

A security-hardened fork of "Simply Show Hooks". Replaces the compromised original (CVE-2024-6297) and patches unlisted Cross-Site Scripting (XSS)…

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

Link sources to sinks in C# applications.

Open-source, cross-platform, multi-purpose security auditing tool


OWASP ASST (Automated Software Security Toolkit) | A Novel Open Source Web Security Scanner.

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

CVE's I found. technical writeups, expolitation examples and fuzzing sessions walkthroughs

The Secure Coding Practices Quick-reference Guide from OWASP

Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability

Static code audit of CVE-2024-57521, an authenticated SQL injection in RuoYi-Vue's generator module, with source-to-sink analysis and a %0b filter…

CVE-2026-49268 — Analysis and Remediation of an LDAP Injection Authentication Bypass Vulnerability

Research-only AI watermark robustness toolkit: local reverse proxy strips C2PA/EXIF/XMP, Unicode, image/audio stego, OOXML/PDF metadata, and scans…

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.