
awesome-nodejs-security
Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

A list of awesome penetration testing tools and resources.

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

A collection of smart contract vulnerabilities along with prevention methods

Enterprise-grade static code analysis platform with multi-language support, security vulnerability detection, code quality metrics, and DevOps…

A collection of my Semgrep rules to facilitate vulnerability research.

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

OWASP ASST (Automated Software Security Toolkit) | A Novel Open Source Web Security Scanner.

Curated Semgrep rule repository for GitLab SAST, providing static analysis patterns to detect security vulnerabilities across multiple programming…

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

The Secure Coding Practices Quick-reference Guide from OWASP

Curated weggli queries for static analysis of C/C++ code to identify dangerous functions, stack issues, and malloc overflow vulnerabilities.

Curated database of Apple internal artifacts (entitlements, frameworks, device versions) with API, CLI, and WebUI for iOS/macOS security research and…

Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

Research-only AI watermark robustness toolkit: local reverse proxy strips C2PA/EXIF/XMP, Unicode, image/audio stego, OOXML/PDF metadata, and scans…

CVE-2026-39259

Clickbait. The CVE is AI slop.