
detect-secrets
An enterprise friendly way of detecting and preventing secrets in code.

An enterprise friendly way of detecting and preventing secrets in code.

Simple Anti-cheat library for applications that use C++ on windows. #PastedProtection

Analysis and exploitation code for CVE-2024-23673, a vulnerability in Apache Sling Servlet Resolver, enabling targeted security testing of…

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

Proof-of-concept exploit for CVE-2026-22686, demonstrating remote code execution in Node.js ESM sandboxes via process.getBuiltinModule to bypass…

Self-contained Docker lab demonstrating CVE-2007-4559 (TarSlip) directory traversal via Python's tarfile module. Includes vulnerable and fixed APIs,…

Metasploit exploit module for CVE-2024-6366, an unauthenticated file upload remote code execution in WordPress User Profile Builder before 3.11.8,…

Major Security Vulnerability on PrestaShop Websites - CVE-2022-31101

Fork of lodash.template with CVE-2021-23337 fix (command injection via variable option)

PrestaShop <1.7.8.9 Fix for CVE-2023-30839 and CVE-2023-30545

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest! https://snuffleupagus.rtfd.io

CodeQL query test for CVE-2023-24329, demonstrating static analysis detection of a specific vulnerability in Python's urllib.parse module.

pluck-CMS-4.7.20-code-injection-vulnerability

Metasploit module that exploits a WordPress unserialization vulnerability (CVE-2024-31211) in WP_HTML_Token to achieve remote code execution.

Pluck v4.7.18 - Remote Code Execution (RCE)

Code execution/injection technique using DLL PEB module structure manipulation

CVE-2026-11837: local privilege escalation in the ansible.posix authorized_key module via symlink-following chown. Technical writeup; sibling of…

Detailed analysis and PoC for CVE-2025-67887/86 RCE in 1C-Bitrix Translate module, including exploit chain, CVSS scoring, and mitigation…