
PoC-CVE-2025-25200
ReDoS explorando backtracking em regex, resultando em consumo excessivo de CPU e negação de serviço (DoS) em aplicações Node.js.

ReDoS explorando backtracking em regex, resultando em consumo excessivo de CPU e negação de serviço (DoS) em aplicações Node.js.

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

Static analysis of wordpress plugins

A Chrome extension static analysis tool to help aide in security reviews.

A hybrid security scanner for detecting CVE-2025-55182 in Next.js and Waku applications. Features combined static code analysis and safe dynamic…

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

A static analysis security vulnerability scanner for Ruby on Rails applications

Dawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.

A source code static analysis platform for AppSec enthusiasts.

a javascript static security analysis tool

🛡️ Scan and assess vulnerabilities in Next.js/Waku with the CVE-2025-55182-Scanner, combining static and dynamic analysis for robust security.

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

ParrotNG is a tool capable of identifying Adobe Flex applications (SWF) vulnerable to CVE-2011-2461

Prevent PHP vulnerabilities similar to CVE-2016-10033 and CVE-2016-10045.

Affected versions of this package are vulnerable to Prototype Pollution.

Security scanner to detect CVE-2025-55182 & CVE-2025-66478 vulnerabilities in React Server Components (RSC) projects

Static web application for viewing SBOMs and performing on-demand vulnerability scanning with osv.dev. Easily deployable to GitHub/GitLab Pages.