
sast-scan-action
GitHub Action for Offensive360 SAST scans and SARIF results. See the open-source program for eligibility and setup.

GitHub Action for Offensive360 SAST scans and SARIF results. See the open-source program for eligibility and setup.

pluck-CMS-4.7.20-code-injection-vulnerability

WordPress Passster Plugin <= 4.2.18 is vulnerable to Cross Site Scripting (XSS)

Detect and patch vulnerable Apache Commons Text in Java JAR/WAR artifacts; fingerprint classes and scan bytecode for CVE-2022-42889 (Text4Shell) call…


Educational examples porting Linux kernel vulnerabilities to Rust, featuring intentionally vulnerable code and exploits for learning kernel security…

Nuclio Dashboard (NOP mode) accepts unauthenticated POST /api/functions. The spec.handler field isn't path-validated, so…

GitHub RCE via X-Stat Push Option Injection

Proof-of-concept exploit for CVE-2024-4577, a PHP CGI argument injection vulnerability enabling remote code execution via crafted HTTP requests.

PoC of CVE-2025-22710

GiveWP PHP Object Injection exploit

GiveWP PHP Object Injection exploit

Disclosure for CVE-2025-13156

Scripts for Analysis of a RCE in Moodle Calculated Questions (CVE-2024-43425)

Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass…

The code for personally reproducing the corresponding vulnerability

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses MultipartFile.transferTo() to…

Detection for CVE-2025-4427 and CVE-2025-4428