


Minimal security backport for CVE-2026-8726 in georgringer/news 8.6.0

Synthetic CWE-120 stack buffer overflow variant of CVE-2020-8597 (pppd EAP) as a CodeQL static-analysis target

CLI tool to scan codebases for quantum-vulnerable cryptography

The ASN1_STRING_set() function takes an `int` length, make sure the argument is not inadvertently truncated when it is called from asn1_ex_c2i().

PHP script to detect CVE-2015-6835 (session deserialization vulnerability) by analyzing source code for unsafe unserialize() calls in session…

CVE-2026-39259

Proof-of-concept exploit for terminal escape sequence injection via malicious filenames that hides Flawfinder's scan findings; fixed in version…

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

Cursor plugin for Hono v4 (TypeScript edge web framework). 59 LLM regressions with BAD/CORRECT pairs. Pinned to hono ^4.12.19 (>= 4.9.7 for…

解决网络安全漏洞

A CodeQL query to find CVE 2022-35737

Bookea-tu-Mesa is vulnerable to SQL Injection

Fix prototype pollution vulnerability (CVE-2023-26136) for tough-cookie package

AWS Serverless Security

Open-source, cross-platform, multi-purpose security auditing tool