
hexora
Static analysis of malicious Python code

Static analysis of malicious Python code

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

Educational demonstration of CVE-2007-4559 Python tarfile symlink attack with a script showing why os.path.realpath() fails to prevent extraction…

Fastest filesystem scanner for log4shell (CVE-2021-44228, CVE-2021-45046) and other vulnerable (CVE-2017-5645, CVE-2019-17571, CVE-2022-23305,…

Applications that are vulnerable to the log4j CVE-2021-44228/45046 issue may be detectable by scanning jar, war, ear, zip files to search for the…

Proof-of-concept exploit for CVE-2024-5082, a remote code execution vulnerability in Sonatype Nexus Repository Manager 2 via crafted Maven artifacts…

Python reference implementation of The Update Framework (TUF)

Community-owned database of security advisories for Python packages on PyPI, providing structured vulnerability data in OSV format for integration…

Proof-of-concept exploit for CVE-2024-55587 in libarchive, demonstrating unsafe extraction via malicious ZIP files.

CVE-2025-47273 — setuptools path traversal PoC

Python source code auditing and static analysis on a large scale

CVE-2025-55182 Detector. Find which of your GitHub repositories are exposed to the critical React/Next.js RCE vulnerability and generate a clean…

Checks all maintainers of all NPM and Pypi packages for hijackable packages through domain re-registration

Python demo simulating CVE-2024-3094: a supply chain backdoor in XZ Utils with a trigger-based stealth activation.

Aggregates vulnerability data from multiple databases into CycloneDX SBOMs, generating deduplicated VEX, HTML, and GitLab-compatible reports for…

Detections for CVE-2021-44228 inside of nested binaries

Portable security rules for the action boundary of AI agents

CLI tool and library for generating a Software Bill of Materials from container images and filesystems