
DockSec
AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

AI-powered Docker security scanner that explains vulnerabilities in plain English. An OWASP Lab Project.

The credit score for npm packages. Analyze package reputation, maintenance, security, publisher trust, and ecosystem health before you install any…

Proof of concept for CVE-2024-24590

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

Alat ini mendeteksi potensi kerentanan React2Shell (CVE-2025-55182) dalam proyek React dengan memeriksa: - File `package.json` dan file lock untuk…

Protection against Model Serialization Attacks

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

A vulnerability scanner for container images and filesystems

OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.

Proof-of-concept for CVE-2021-26700: remote code execution in the VSCode npm-script extension via malicious workspace settings.json, with detailed…

Created after the disclosure of CVE-2021-44228. Bash script that detects Log4j occurrences in your projects and systems, allowing you to get insight…

Minimal CVE-2024-3094 reference repository documenting the xz backdoor vulnerability, affected versions (5.6.0/5.6.1), and mitigation steps. Includes…

KubeClarity is a tool for detection and management of Software Bill Of Materials (SBOM) and vulnerabilities of container images and filesystems

Read-only safety scanner for Claude Code projects. Catches CVE-2025-59536, statusLine injection, prompt injection, and more.

Find, verify, and analyze leaked credentials

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Vulnerability scanner written in Go which uses the data provided by https://osv.dev

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…