
CVE-2017-8046
Demonstrates exploitation of CVE-2017-8046 in a Spring Boot application, including a SpEL injection payload and dependency-check verification for…

Demonstrates exploitation of CVE-2017-8046 in a Spring Boot application, including a SpEL injection payload and dependency-check verification for…

Post Saint <= 1.3.1 plugin for WordPress Arbitrary File Upload

A fast, portable, and lightweight COSE + CBOR implementation for embedded systems. Supports PQC, FIPS 140-3, DO-178, and MISRA C. Powered by wolfSSL.

GitHub Action for Offensive360 SAST scans and SARIF results. See the open-source program for eligibility and setup.

Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)

Nuclio Dashboard (NOP mode) accepts unauthenticated POST /api/functions. The spec.handler field isn't path-validated, so…

Detect exposed API keys on GitHub commits.

PoC for CVE-2020-0601 - CryptoAPI exploit

CVE-2023-46818 Python3 Exploit for ISPConfig <= 3.2.11 (language_edit.php) PHP Code Injection Vulnerability


The code for personally reproducing the corresponding vulnerability

Detect and patch vulnerable Apache Commons Text in Java JAR/WAR artifacts; fingerprint classes and scan bytecode for CVE-2022-42889 (Text4Shell) call…

Proof of Concept for CVE-2020-14295.

WordPress Passster Plugin <= 4.2.18 is vulnerable to Cross Site Scripting (XSS)

Detection for CVE-2025-4427 and CVE-2025-4428

Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass…

CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).

GiveWP PHP Object Injection exploit