Live demo

See ArgusSecure findings, without signing up.

Three pre-scanned demo projects — synthetic by design. Real OWASP 2025 tagging, real evidence shape, real fix recommendations. Click any finding to inspect it.

About this demo. All findings below come from a synthetic codebase + dependency manifest + sample S3 configuration. ArgusSecure never scans arbitrary targets in demo mode — your own projects need explicit authorization and (for web apps) domain verification before any scan runs.

Demo — Vulnerable Dependencies

package.json
6 findings
  • High
    CVE-2021-23337: Command injection in lodash template (lodash@4.17.20)
    lodash@4.17.20
    Versions of lodash before 4.17.21 are vulnerable to command injection via template().
    CWE-94A03:2025sca
  • Critical
    CVE-2021-44906: Prototype pollution in minimist (minimist@1.2.5)
    minimist@1.2.5
    minimist before 1.2.6 is vulnerable to prototype pollution.
    CWE-1321A03:2025sca
  • High
    CVE-2021-3749: Regular Expression Denial of Service in axios (axios@0.21.0)
    axios@0.21.0
    axios before 0.21.2 is vulnerable to ReDoS via trim().
    CWE-1333A03:2025sca
  • High
    CVE-2022-24999: qs vulnerable to prototype pollution via Express (express@4.17.1)
    express@4.17.1
    Express bundling vulnerable qs version allows prototype pollution.
    CWE-1321A03:2025sca
  • Medium
    CVE-2021-32640: ReDoS in ws Sec-WebSocket-Protocol parser (ws@7.4.5)
    ws@7.4.5
    ws before 7.4.6 has a ReDoS in the Sec-WebSocket-Protocol header.
    CWE-1333A03:2025sca
  • High
    CVE-2022-23529: Insecure default algorithm in jsonwebtoken (jsonwebtoken@8.5.1)
    jsonwebtoken@8.5.1
    jsonwebtoken before 9.0.0 is vulnerable to algorithm confusion attacks.
    CWE-327A03:2025sca