
gh-workflow-auditor
Script to audit GitHub Action Workflow files for potential vulnerabilities.

Script to audit GitHub Action Workflow files for potential vulnerabilities.

A python script to create a fake GitHub runner and hijack pipeline jobs to leak CI/CD secrets.

Created after the disclosure of CVE-2022-22965 and CVE-2022-22963. Bash script that detects Spring Framework occurrences in your projects and…

CVE-2025-55182 Detector. Find which of your GitHub repositories are exposed to the critical React/Next.js RCE vulnerability and generate a clean…

A simple script to remove Log4J JndiLookup.class from jars in a given directory, to temporarily protect from CVE-2021-45046 and CVE-2021-44228.

This repository contains a Bash script and a one-liner command to verify if a system is running a vulnerable version of the "xz" utility, as…


Script to handle CVE 2022-42889

A script to change OpenSSL versions on Ubuntu to 1.1.1q to protect against CVE-2022-2097.

Applications that are vulnerable to the log4j CVE-2021-44228/45046 issue may be detectable by scanning jar, war, ear, zip files to search for the…

Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)

CVE-2024-24590 ClearML RCE&CMD POC

Script to detect CVE-2024-3094.


A lightweight, recursive Bash script to detect Next.js and React Server DOM versions vulnerable to CVE-2025-55182 (React2Shell) in local projects.


Log4J Updater Bash Script to automate the framework update process on numerous machines and prevent the CVE-2021-44228

Script to obfuscate a payload the same way as it was done by the XZ utils attack (CVE-2024-3094)