All resources
Topic

cve

5 resources across 3 kinds

Frameworks & agents

  1. Vul-RAG, a knowledge-level retrieval-augmented-generation framework for LLM-based vulnerability detection: it extracts vulnerability knowledge from CVEs into a knowledge base and uses it to judge whether given code is vulnerable. Ships the LinuxVul benchmark (4,667 vulnerable/patched function pairs from 2,174 Linux-kernel CVEs across the top-10 CWEs); the authors report finding 10 previously-unknown kernel bugs, 6 receiving CVE assignments.

    Open ↗
  2. CVE-Factorydual-usehigh-riskcloud cost

    A multi-agent pipeline that automates end-to-end CVE reproduction: it researches CVE details, generates test cases, builds Docker environments, and validates both the exploit and the patch. It powers the LiveCVEBench evaluation and produces training traces for security-focused LLMs.

    Open ↗

Benchmarks

  1. An OpenSSF benchmark containing code and metadata for over 200 real-life CVEs, with tooling to evaluate Static Analysis Security Testing (SAST) solutions by measuring vulnerability detection rates and false positives against vulnerable/patched open-source code.

    Open ↗

References

  1. A vulnerability-intelligence platform that aggregates CVEs from seven public sources (GHSA, NVD, CVEfixes, MegaVul, BigVul, MoreFixes, Security DPO) into a canonical schema and indexes them with vector embeddings for code-similarity, pattern-based, cross-project and natural-language search. Built on Python/FastAPI with ChromaDB and transformer embeddings, it can also generate Semgrep/CodeQL detection rules and exposes REST and CLI interfaces.

    Open ↗
  2. Curated catalogue of macOS/iOS security research: a large CVE table (2014–2025) mapped to affected components with links to technical write-ups, plus references to analysis tools (IOKit probing, dyld cache analysis, kernel driver analyzers), fuzzing frameworks, and conference talks (Black Hat, CanSecWest, DEFCON).

    Open ↗