
CVE-2026-13158
Proof-of-concept exploit and technical advisory for an Admin+ arbitrary file upload to remote code execution vulnerability in Everest Toolkit…

Proof-of-concept exploit and technical advisory for an Admin+ arbitrary file upload to remote code execution vulnerability in Everest Toolkit…

SyncShield - Browser Extension to Detect Unsafe Rsync Commands (CVE-2018-5764)



Bandit is a tool designed to find common security issues in Python code.

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)

PHP static application security testing (SAST) tool that performs taint analysis to detect XSS, SQL injection, and other vulnerabilities using…

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

A CodeQL query to find CVE 2022-35737

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

A collection of my Semgrep rules to facilitate vulnerability research.

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

Curated Ghidra scripts to automate reverse engineering and vulnerability analysis: locate insecure functions, extract decompiler pseudocode, fix…

Curated Semgrep rule repository for GitLab SAST, providing static analysis patterns to detect security vulnerabilities across multiple programming…

Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability

AST-free heuristic knowledge graph engine for deep repository intelligence and zero-trust security scanning. Integrates as a GitLab CI/CD component,…