
SSTImap
Automatic SSTI detection tool with interactive interface

Automatic SSTI detection tool with interactive interface

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…

Django application that performs SAST and Malware Analysis for Android APKs

CVE-2022-41852 Proof of Concept (unofficial)

In Dolibarr 17.0.0 with the CMS Website plugin (core) enabled, an authenticated attacker can obtain remote command execution via php code injection…

ADT is a toolset designed to help model application behavior, research and test security vulnerabilities, and facilitate reversing hostile code.

Hotel Druid 3.0.3 Code Injection to Remote Code Execution

个人挖掘出来的漏洞CVE-2021-43503

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit…


I couldn’t find a PoC for CVE-2023-30253, so I developed an effective one


CVE-2020-26258 && XStream SSRF