Benchmark · web-cve
CVE-Bench
Forty containerized critical real-world web CVEs with deterministic/executable graders for testing verified completion.
Tagsweb-cve
More benchmarks
- BountyBenchbug-bountyBug-bounty evaluation of 40 historical bounties across 25 real systems with separate Detect, Exploit, and Patch tasks and executable graders.
- CWE-Bench-Javawhite-box-javaJava white-box discovery/exploitation/patching benchmark from the IRIS-SAST project.
- Cybenchctf-long-horizonCTF benchmark for long-horizon planning and recovery.
- CyberGymsource-analysisLarge-scale benchmark for source analysis and PoC generation.
- Jev Prompt-Injection Benchmark (JurijZ)eval-harnessMIT-licensed one-notebook benchmark that sends 116 labeled prompts to TypeSafe's hosted system_one API and reports per-call latency plus a confusion matrix of its prompt-injection verdicts; needs a TypeSafe account.
- jev-sec-bencheval-harnessMIT-licensed Go benchmark that scores TypeSafe's hosted Jev model on 662 labelled messages (263 injections) and 200 matched vulnerable/secure code pairs; needs a TypeSafe API key, and the documented runner is not in the tree.