a static analysis tool for finding vulnerabilities in C/C++ source code
☆585May 17, 2026Updated 4 months ago
Alternatives and similar repositories for flawfinder
Users that are interested in flawfinder are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- static analysis of C/C++ code☆6,768Updated this week
- A collection of my Semgrep rules to facilitate vulnerability research.☆876Sep 25, 2026Updated last week
- Splint - annotation-assisted static program checker☆332Jul 19, 2026Updated 2 months ago
- cwe_checker finds vulnerable patterns in binary executables☆1,361Sep 28, 2026Updated last week
- CodeChecker is an analyzer tooling, defect database and viewer extension for static and dynamic analyzer tools.☆2,628Updated this week
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- ☆100Nov 10, 2021Updated 4 years ago
- Static code analysis test source code☆37Aug 30, 2023Updated 3 years ago
- ☆18Aug 5, 2020Updated 6 years ago
- ⚙️ A curated list of static analysis (SAST) tools and linters for all programming languages, config files, build tools, and more. The foc…☆14,827Updated this week
- Open-source code analysis platform for C/C++/Java/Binary/Javascript/Python/Kotlin based on code property graphs. Discord https://discord.…☆3,554Updated this week
- Flint++ is cross-platform, zero-dependency port of flint, a lint program for C++ developed and used at Facebook.☆264Sep 25, 2019Updated 7 years ago
- A C/C++ Code Vulnerability Dataset with Code Changes and CVE Summaries☆371Mar 25, 2021Updated 5 years ago
- BinAbsInspector: Vulnerability Scanner for Binaries☆1,676Jun 17, 2024Updated 2 years ago
- A Coverage-Based fuzzing tools☆23Aug 9, 2021Updated 5 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- EMBA - The firmware security analyzer☆3,690Updated this week
- Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.☆16,901Updated this week
- ☆15Jan 24, 2023Updated 3 years ago
- ThreatBox is a standard and controlled Linux based attack platform. I've used a version of this for years. It started as a collection of …☆77Nov 19, 2024Updated last year
- A collection of my weggli patterns to facilitate vulnerability research.☆161Aug 2, 2026Updated 2 months ago
- Karonte is a static analysis tool to detect multi-binary vulnerabilities in embedded firmware☆434Sep 18, 2021Updated 5 years ago
- Analyse binaries for missing security features, information disclosure and more...☆88Aug 7, 2023Updated 3 years ago
- Fuzzware's main repository. Start here to install.☆387Jun 27, 2026Updated 3 months ago
- A LLVM-based static analysis framework.☆1,058Sep 30, 2026Updated last week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A set of Code-ql/Joern queries to find vulnerabilities☆67May 22, 2021Updated 5 years ago
- Fuzzing IoT Devices Using the Router TL-WR902AC as Example☆133Nov 15, 2025Updated 10 months ago
- Static Value-Flow Analysis Framework for Source Code☆1,713Updated this week
- Exploit for uTorrent vulnerability CVE-2020-8437 by mavlevin☆11Feb 1, 2026Updated 8 months ago
- An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.☆599Jun 10, 2026Updated 3 months ago
- Binary code-coverage fuzzer for macOS, based on libFuzzer and LLVM☆182Aug 9, 2026Updated last month
- Evolving fuzzers with large language models☆18Dec 14, 2023Updated 2 years ago
- Firmware Analysis and Comparison Tool☆1,466Oct 1, 2026Updated last week
- Code and artifacts related to the Asia CCS 2022 paper☆38Nov 8, 2021Updated 4 years ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- A collection of my Ghidra scripts to facilitate reverse engineering and vulnerability research.☆303Aug 2, 2026Updated 2 months ago
- Companion to the "Introduction to VirtualBox security research" Blog Post☆35Apr 26, 2022Updated 4 years ago
- A Binary Ninja plugin for vulnerability research.☆301Jun 19, 2026Updated 3 months ago
- ☆231Jul 25, 2024Updated 2 years ago
- AFL++ is a state-of-the-art fuzzer, and #1 in benchmarks. It was originally based on AFL. Today it comes with qemu 5.1, collision-free co…☆6,784Updated this week
- A fork and successor of the Sulley Fuzzing Framework☆2,362Sep 21, 2026Updated 2 weeks ago
- ☆10Sep 24, 2019Updated 7 years ago