
log4jhound
Created after the disclosure of CVE-2021-44228. Bash script that detects Log4j occurrences in your projects and systems, allowing you to get insight…

Created after the disclosure of CVE-2021-44228. Bash script that detects Log4j occurrences in your projects and systems, allowing you to get insight…
Proof-of-concept demonstrating a hardlink path traversal in the tar npm package, allowing overwrite of files outside the extraction directory via…

Security scanner for AI/ML model files. Detects malicious code, backdoors, and vulnerabilities before deployment

Script to audit GitHub Action Workflow files for potential vulnerabilities.

Builds a SQLite database of Maven artifacts (ArtifactID, GroupID, Version, SHA1) for Trivy's Java component vulnerability detection, enabling scans…

Single-binary scanner for CVE-2021-44228 (Log4Shell) that detects vulnerable log4j versions in JAR/WAR/EAR files and applies mitigation patches by…

Ghidra-based tool for detecting and analyzing the Log4j vulnerability (CVE-2021-44228) in binary files, enabling reverse engineering of affected…

Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and…

Patched version of the uploader.swf and uploaderSingle.swf to fix CVE-2011-2461

Discover Log4Shell vulnerability [CVE-2021-44832]

Discover and remediate Log4Shell vulnerability [CVE-2021-45105]

Exploit for CVE-2020-35460 targeting MPXJ project management library, enabling arbitrary code execution via crafted project files in Java, .Net, and…

Generate malicious files using recently published homoglyphic-attack (CVE-2021-42694)

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

Scans compiled Java archives (JAR/WAR) for ECDSA algorithm usage to detect CVE-2022-21449 vulnerability. Recursively examines .class files with…

Demonstration exploit for CVE-2022-32223: DLL hijacking in Node.js on Windows via malicious providers.dll, targeting OpenSSL installations.

Applications that are vulnerable to the log4j CVE-2021-44228/45046 issue may be detectable by scanning jar, war, ear, zip files to search for the…

GitHub Action that scans ML model files for malicious code and security vulnerabilities