
monty
A minimal, secure Python interpreter written in Rust for use by AI

A minimal, secure Python interpreter written in Rust for use by AI

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

Dynamic branch-divergence finder for native code -- traces two Frida executions and finds the exact instruction where they diverge.

PoC for CVE-2026-63030 + CVE-2026-60137, AKA WP2Shell

Comprehensive Java vulnerability lab with vulnerable and fixed code, attack scenarios, source/sink audit notes, and secure coding guidance for…

Source code for the Binaries of OWASP WrongSecrets

POC of CVE-2021-42574 for solidity and solc compiler


FreePBX 未认证SQL注入导致远程代码执行,FreePBX 15 (低于 15.0.66)、16 (低于 16.0.89)、17 (低于 17.0.3)。该漏洞位于商业化“endpoint”模块中,因对用户输入过滤不严,允许未认证的攻击者绕过管理员权限,执行SQL注入,并最终实现远程代码执行

Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)


WordPress REST API SQLi to RCE PoC (CVE-2026-63030 & CVE-2026-60137)

awslabs/sockeye Code injection via unsafe YAML loading CVE-2021-43811

PowerShell Obfuscation Detection Framework

Source code for the book "Black Hat Python" by Justin Seitz. The code has been fully converted to Python 3, reformatted to comply with PEP8 standards…

A vulnerable version of Rails that follows the OWASP Top 10

Critical use-after-free vulnerability discovered in Tinyproxy

Apache Syncope: User self-service privilege escalation