
external_v8_AOSP10_r33_CVE-2020-0240
Research repository for CVE-2020-0240 in V8 JavaScript engine, providing source code and analysis for vulnerability understanding and exploitation.

Research repository for CVE-2020-0240 in V8 JavaScript engine, providing source code and analysis for vulnerability understanding and exploitation.

Static analysis scanner for CVE-2020-11023 XSS vulnerabilities in JavaScript. Detects vulnerable jQuery versions and dangerous DOM manipulation…

PoC — frontmatter-driven arbitrary JavaScript execution in Note Toolbar for Obsidian (GHSA-q8cw-3m8c-5pf2, CVE-2026-87002, CVSS 7.0).

Repository containing V8 JavaScript engine source code with a specific commit for CVE-2021-0396, likely for vulnerability research and exploitation.

Fast, configurable HTML sanitization library for preventing XSS and malicious code injection from untrusted user input. Provides a policy-driven API…

Proof-of-concept exploit and lab environment for CVE-2026-27495

A patched version of the V8 JavaScript engine addressing CVE-2021-0393, providing a secure baseline for Android 10 R33 builds.

Fix prototype pollution vulnerability (CVE-2023-26136) for tough-cookie package

Obfuscates PowerShell and JavaScript scripts using tree-sitter-based parsing with multiple configurable impostor profiles for stealth, size, and…

YAML-based proof-of-concept for CVE-2025-59528, demonstrating remote code execution in Flowise via the CustomMCP node's unsafe JavaScript evaluation.

Java library for fast, configurable HTML sanitization from untrusted sources. Uses policy-driven scanning to remove malicious JavaScript and CSS,…

PoC repository for CVE-2025-68147: Stored Cross-Site Scripting (XSS) in OpenSourcePOS. Vulnerability allows privilege escalation via malicious…

Proof-of-concept for CVE-2025-60655: Remote Code Execution via unrestricted file upload bypassing client-side JavaScript validation, enabling…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Obfuscates JavaScript and Node.js code with variable renaming, string encryption, control flow flattening, and anti-debugging to protect source code…

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of…

nodejsscan is a static security code scanner for Node.js applications.

Tree-sitter based static vulnerability scanner with pattern matching and taint-flow analysis for multi-language source code. Outputs findings as…