
POC-CVE-2026-63030-CVE-2026-60137-
Exploit chain for WordPress Core using REST API route-confusion and SQL injection for unauthenticated RCE, privilege escalation, and full server…

Exploit chain for WordPress Core using REST API route-confusion and SQL injection for unauthenticated RCE, privilege escalation, and full server…

Demonstrates CVE-2026-18953 arbitrary file write in an MCP server's get_resource tool by abusing savePath path traversal; includes vendored…

Damn Vulnerable MCP Server




An implementation of a vulnerable MCP server using mcp-go


Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan,…


mcp-remote exposed to OS command injection

Authenticated API Key Exposure in Nagios Log Server 2024R1.3.1

Post-quantum hybrid encryption library combining X25519 + ML-KEM-768 with AES-256-GCM

Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security…

Scalable API key server for issuing, verifying, and revoking credentials with token derivation for fine-grained capability tokens. Supports…


A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.