
enforcement-coverage
Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

PHP script to detect CVE-2015-6835 (session deserialization vulnerability) by analyzing source code for unsafe unserialize() calls in session…

GitHub Action for Offensive360 SAST scans and SARIF results. See the open-source program for eligibility and setup.

Generates five .NET deserialization payload formats for CVE-2026-56158, delivers them over HTTP/SOAP/JSON endpoints, includes mock server, scanner,…

A Bitbucket Pipe to trigger SonarCloud analysis

Cursor plugin for Hono v4 (TypeScript edge web framework). 59 LLM regressions with BAD/CORRECT pairs. Pinned to hono ^4.12.19 (>= 4.9.7 for…

解决网络安全漏洞

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

SyncShield - Browser Extension to Detect Unsafe Rsync Commands (CVE-2018-5764)

Scans Git repositories for hardcoded secrets, keys, and passwords using Gitleaks, integrating security into Bitbucket Pipelines with Code Insights…

CodeQL-based scanner that inventories cryptographic function calls across repositories and GitHub organizations, producing a Cryptographic Bill of…

Unpack and deobfuscate VMProtect 2 protected binaries with an emulation-based VM explorer, handler profiler, and experimental LLVM recompiler for…

Link sources to sinks in C# applications.

The iOS Security Testing Framework

Sourcetrail - free and open-source interactive source explorer

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

AWS Serverless Security