
cs50-cybersecurity-final-project
Technical analysis of the XZ Utils backdoor (CVE-2024-3094), explaining the supply chain attack, obfuscation techniques, and impact on OpenSSH via…

Technical analysis of the XZ Utils backdoor (CVE-2024-3094), explaining the supply chain attack, obfuscation techniques, and impact on OpenSSH via…

Computes a criticality score for open source projects from repository, contributor, and dependency metrics to prioritize security improvements.

Found a 0-Day in Ghidra: Shared Project File Became a Code Execution Vector

Scans project dependencies for dependency confusion vulnerabilities and checks package owner email takeover risks across multiple registries (npm,…

Modular security toolkit for autonomous agents providing static analysis, configuration auditing, runtime monitoring, and supply chain verification…

SEDATED® Project (Sensitive Enterprise Data Analyzer To Eliminate Disclosure)

DugganUSA threat-intelligence contributions to the IETF Hackathon — real-world agentic-attack benchmark vectors, CVE-2026-33697 attestation analysis,…

Software composition analysis tool that detects publicly disclosed vulnerabilities in project dependencies using CPE matching, generating detailed…

Multi-language detection scripts for CVE-2025-55182 (React2Shell) that scan package.json files to identify vulnerable React dependency versions and…

A simple project to check coverage of Log4J vuln CVE-2021-44228 (and related)

simple application with a CVE-2022-45688 vulnerability

simple application with a CVE-2022-45688 vulnerability

Exploit for CVE-2020-35460 targeting MPXJ project management library, enabling arbitrary code execution via crafted project files in Java, .Net, and…

Check with Maven on CVE-2011-1475

Proof of concept for CVE-2024-24590

general purpose workaround for the log4j CVE-2021-44228 vulnerability

Detects CVE-2025-55182 RCE in React Server Components by scanning npm/pnpm/yarn lockfiles, Docker images, SBOMs, and live URLs. Includes auto-fix,…