
SindriKit
A foundational C library for building operationally credible offensive capabilities

A foundational C library for building operationally credible offensive capabilities

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

pluck-CMS-4.7.20-code-injection-vulnerability

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest! https://snuffleupagus.rtfd.io

Build and query a graph database representation of source code

"In-depth reverse engineering analysis of an advanced multi-phase loader targeting Shellhost.exe, amsi.dll, mstscax.dll, and clbcatq.dll using module…

CVE-2026-11837: local privilege escalation in the ansible.posix authorized_key module via symlink-following chown. Technical writeup; sibling of…

PoC repository for CVE-2025-68147: Stored Cross-Site Scripting (XSS) in OpenSourcePOS. Vulnerability allows privilege escalation via malicious…

PHP-based exploit module targeting CVE-2025-67146 and CVE-2025-67147 for automated vulnerability exploitation and security assessment.

Self-contained Docker lab demonstrating CVE-2007-4559 (TarSlip) directory traversal via Python's tarfile module. Includes vulnerable and fixed APIs,…

An enterprise friendly way of detecting and preventing secrets in code.

Proof-of-concept exploit for CVE-2026-22686, demonstrating remote code execution in Node.js ESM sandboxes via process.getBuiltinModule to bypass…

Fork of lodash.template with CVE-2021-23337 fix (command injection via variable option)

Detailed analysis and PoC for CVE-2025-67887/86 RCE in 1C-Bitrix Translate module, including exploit chain, CVSS scoring, and mitigation…

Bitrix24 <= 25.100.300 (Translate Module) Remote Code Execution Vulnerability

1C-Bitrix <= 25.100.500 (Translate Module) Remote Code Execution Vulnerability

Exploit module for Apache JSPWiki CVE-2019-10078, enabling security testing of Java-based wiki platforms through targeted vulnerability exploitation…

Detection for CVE-2025-42944