
oss-oopssec-store
Security training for the apps you actually ship. Open your browser and start hacking.

Security training for the apps you actually ship. Open your browser and start hacking.

One command to fix CVE-2025-66478 (React 2 Shell RCE) in your Next.js / React RSC app.

Demo consumer for ollama v0.5.0 (vulnerable range for CVE-2024-12886) — endorctl scan target

CRAReady SBOM test fixture — Java/Maven app with Log4Shell (CVE-2021-44228), Spring4Shell, Text4Shell, and other critical CVEs

Reproducer for CVE-2023-3635 in Okio 2.9.0, demonstrating how React Native's version catalog pins a vulnerable dependency, affecting Android apps.

GitHub App to set and enforce security policies

LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests and…

SafeForge is an open-source mobile app hub built on GitLab that enables developers to build, upload, and share applications in a secure, AI-verified…

Spring Boot app with log4j 2.14.1 (CVE-2021-44228) — VulnFix agent test target

A doggo that helps look for security issues in your repositories.

Demo consumer for invokeai 5.0.1 (CVE-2024-10821; version named in CVE prose) — endorctl scan target

Proof-of-concept code for Android APEX key reuse vulnerability

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis