
cve-2021-33879
GameLoop update MITM

GameLoop update MITM
0-day malware detection for binaries, source & scripts (that doesn't suck)

Developer-focused knowledge base of application security vulnerabilities with insecure vs secure code examples, prevention guidance, and OWASP/CWE…

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

GitHub App to set and enforce security policies

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

Security training for the apps you actually ship. Open your browser and start hacking.

Computes a criticality score for open source projects from repository, contributor, and dependency metrics to prioritize security improvements.

python dependency vulnerability scanner, written in Rust.

Demonstrates exploitation of CVE-2017-8046 in a Spring Boot application, including a SpEL injection payload and dependency-check verification for…

OpenSSF Scorecard - Security health metrics for Open Source

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

Exploit for remote command execution in Golang go get command.

GNU IFUNC is the real culprit behind CVE-2024-3094

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

Proof-of-concept for CVE-2021-26700: remote code execution in the VSCode npm-script extension via malicious workspace settings.json, with detailed…

Self-contained Docker lab demonstrating CVE-2007-4559 (TarSlip) directory traversal via Python's tarfile module. Includes vulnerable and fixed APIs,…

Malicious Maven pom.xml that uses "groovy-maven-plugin" to get RCE