
SafeLine
Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Passive Laravel middleware that detects and logs SQL injection, XSS, RCE, bot scanners, and 175+ attack patterns. Features a built-in dashboard,…

Fixes unauthenticated SQL injection in a setup endpoint by replacing raw JDBC queries with ORM parameterization and constant-time token validation.

Automatic SQL injection and database takeover tool

ML-based detection of SQL injection and XSS attacks in API requests using TF-IDF vectorization and logistic regression classification.

Exploit chain for WordPress Core using REST API route-confusion and SQL injection for unauthenticated RCE, privilege escalation, and full server…

High-performance, low-maintenance Nginx module acting as a DROP-by-default WAF, blocking XSS, SQL injection, and other web attacks using simple…

Documentation and proof-of-concept for CVE-2026-42208, a critical pre-authentication SQL injection vulnerability in the LiteLLM AI gateway enabling…

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.

PoC exploit for CVE-2026-32621 demonstrating Apollo Federation deepMerge prototype pollution via crafted GraphQL aliases, with patched-version tests.

Minimal Python PoC for CVE-2026-40179: injects a malicious metric name via unauthenticated Prometheus remote_write to trigger stored XSS in the web…

Intentionally vulnerable Golang programs exposing web, gRPC, and database/sql flaws for security training, vulnerability discovery, and remediation…

JetEngine <= 3.7.7 — Unauthenticated Stored Cross-Site Scripting via CCT REST API