
CVE-2026-0848
nltk.tokenize.StanfordSegmenter dynamically loads external Java .jar files without verification or sandboxing. If an attacker can supply or replace…

nltk.tokenize.StanfordSegmenter dynamically loads external Java .jar files without verification or sandboxing. If an attacker can supply or replace…

一个由AI生成的漏洞验证应用

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)


Executable security regression testing for agentic applications and MCP-integrated systems.

MCP server for Slither static analysis of Solidity smart contracts

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

Detection for CVE-2025-42944

CVE-2025-31324, SAP Exploit

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis

Web services framework for building and developing SOAP, RESTful, and CORBA services with support for WS-Security, WS-Trust, and JAX-WS/JAX-RS APIs.

Reproduction of a high severty security problem that allows XXE (XML eXternal Entity) attacks on Ktor's XML serialization.

Automated testing suite with live traffic record and replay

CVE-2024-11972 in Hunk Companion <1.9.0 allows unauthenticated attackers to exploit insecure REST API endpoints and install vulnerable plugins,…