
local-log4j-vuln-scanner
[Moved to Codeberg] Simple local scanner for vulnerable log4j instances

[Moved to Codeberg] Simple local scanner for vulnerable log4j instances

A vulnerability scanner for container images and filesystems

LD_PRELOAD-based tool that hijacks gcc to inject malicious code into binaries during linking, enabling stealthy backdoor deployment without source…

A tool for finding vulnerable libwebp(CVE-2023-4863)

CLI tool that verifies Docker images for CVE-2018-8115 by checking layers for malicious files, helping ensure safe pulls from Docker Hub.

Shell script to detect TanStack npm supply chain attack indicators (CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx)

Scan codebases for quantum-vulnerable cryptography. Detect RSA, ECDSA, Ed25519, ECDH before Q-Day. CycloneDX CBOM + SARIF output.

Detect CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Fast, accurate scanner with zero false positives.

Simple tool for scanning entire directories for attempts of CVE-2021-44228

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…

Example InSpec profile to detect presence of a malicious rest-client gem (CVE-2019-15224)

One-command scanner for the Mini Shai-Hulud npm supply-chain worm (CVE-2026-45321). Detect before rotating tokens.

Asset-wide detection tool for identifying jsPDF usage related to CVE-2025-68428 Detection only — no exploitation

Detect CVE-2025-54313 eslint-config-prettier supply chain attack IOCs on Windows

Script to detect CVE-2024-3094.

General-purpose data compression library implementing the zlib, deflate, and gzip formats, with thread-safe functions and cross-platform build…

This tool patches the CVE-2021-44228 Log4J vulnerability present in all minecraft versions NOTE THIS TOOL MUST BE RE-RUN after downloading or…

An agent to hotpatch the log4j RCE from CVE-2021-44228.