
roundcube-cve-2025-49113-lab
Hands-on exploitation lab for Roundcube Webmail CVE-2025-49113 (authenticated PHP object deserialization → RCE) to read /secret.txt.

Hands-on exploitation lab for Roundcube Webmail CVE-2025-49113 (authenticated PHP object deserialization → RCE) to read /secret.txt.

Proof-of-concept exploit for CVE-2026-33937, a Handlebars AST injection vulnerability leading to remote code execution in Node.js. Demonstrates…

Proof-of-concept exploit for CVE-2016-2098, demonstrating remote Ruby code execution through Rails render method abuse; intended for security testing…

Proof-of-concept exploit demonstrating the Zip Slip vulnerability (CVE-2019-10743) in mholt/archiver, with a vulnerable server and Python payload for…

C library for stream-oriented XML parsing with a focus on vulnerability analysis and exploitation of CVE-2022-43680, enabling fuzzing and…

Source code repository for Expat 2.1.0, a stream-oriented XML parser library, with focus on analyzing and addressing CVE-2022-43680.

Java security library providing contextual encoders and sanitizers to automatically remediate vulnerabilities like XSS, path traversal, and command…

A fix for the batchOverflow bug https://medium.com/@peckshield/alert-new-batchoverflow-bug-in-multiple-erc20-smart-contracts-cve-2018-10299-511067db65…

Public disclosure for CVE-2023-31584.

Exploit for CVE-2022-25175 targeting Jenkins Pipeline: Multibranch plugin, enabling automated exploitation of a specific vulnerability in CI/CD…

C library for stream-oriented XML parsing, with a focus on analyzing and reproducing CVE-2024-28757 vulnerability in Expat 2.1.0.

CVE-2021-44228

Exploit script for CVE-2024-34102, an XXE vulnerability in Adobe Commerce allowing arbitrary code execution via crafted XML documents.

CVE-2022-37205 POC

Demonstrating Remote Code Execution Vulnerability via Pickle Serialization in ClearML

CVE-2022-37207 POC

Fix prototype pollution vulnerability (CVE-2023-26136) for tough-cookie package