
log4j-log4shell-affected
Lists of affected components and affected apps/vendors by CVE-2021-44228 (aka Log4shell or Log4j RCE). This list is meant as a resource for security…

Lists of affected components and affected apps/vendors by CVE-2021-44228 (aka Log4shell or Log4j RCE). This list is meant as a resource for security…

This repository contains potential security patches for the Magento APSB22-48 and CVE-2022-35698 security vulnerability

This is an incident response playbook we created for the Vercel April 2026 compromise

This opensource project dedicated to implementing Enterprise level AI-SPM. By doing so organizations can proactively protect their AI systems from…

This repository contains a Bash script and a one-liner command to verify if a system is running a vulnerable version of the "xz" utility, as…

A comprehensive guide to software supply chain security. This open-source manuscript provides security professionals and developers with practical…

This repository provides a comprehensive security remediation of denial-of-service and allocation of resources without limits or throttling security…

CVE-2018-6574 this vulnerability impacts Golang go get command and allows an attacker to gain code execution on a system by installing a malicious…

This repository contains a solution for the CVE-2023-26136 vulnerability.

This is the exploit of CVE-2018-6574: go get RCE

It was determined that malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. # It was determined that only…

CVE-2023-37478 showcases how a difference in npm and pnpm install packages that could be exploited by a well crafted tar.gz packge. This repo shows a…

This tool patches the CVE-2021-44228 Log4J vulnerability present in all minecraft versions NOTE THIS TOOL MUST BE RE-RUN after downloading or…

Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Getting a handle on container security


Checks all maintainers of all NPM and Pypi packages for hijackable packages through domain re-registration