
semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Curated directory of Node.js security tools, static analyzers, vulnerability scanners, and educational resources covering OWASP Top 10, supply chain…

OSWE, OSEP, OSED, OSEE

Curated catalog of Solidity smart contract vulnerability patterns with categorized examples, prevention methods, and LLM-optimized references for…

Enterprise-grade static code analysis platform with multi-language support, security vulnerability detection, code quality metrics, and DevOps…

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

OWASP ASST (Automated Software Security Toolkit) | A Novel Open Source Web Security Scanner.

CVE's I found. technical writeups, expolitation examples and fuzzing sessions walkthroughs

A list of awesome penetration testing tools and resources.

The Secure Coding Practices Quick-reference Guide from OWASP

Curated Semgrep rule repository for GitLab SAST, providing static analysis patterns to detect security vulnerabilities across multiple programming…

BianryNinja plugin for identifying vulnerabilities in decompiled binaries with both programmatic scans and LLM support.

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability

Clickbait. The CVE is AI slop.

CVE-2026-39259

AI-powered CLI tool that reviews code for security vulnerabilities, bugs, and anti-patterns using LLMs. Supports local and cloud providers, git…