
Groovy-scripting-engine-CVE-2015-1427
Docker-based lab environment for CVE-2015-1427 ElasticSearch Groovy sandbox bypass and remote code execution, demonstrating two POC methods with Java…

Docker-based lab environment for CVE-2015-1427 ElasticSearch Groovy sandbox bypass and remote code execution, demonstrating two POC methods with Java…

Demonstrating Remote Code Execution Vulnerability via Pickle Serialization in ClearML

a scenario based on CVE-2022-25845 yielding a TP for metadata based SCA but a FN if the callgraph is used

Patched tough-cookie v2.5.0 fixing CVE-2023-26136 prototype pollution vulnerability with Object.create(null) in MemoryCookieStore, including exploit…

Curated Java web framework vulnerability (CVE-2016-5394) for Apache Sling, designed for security testing, exploitation practice, and vulnerability…

Step-by-step technical analysis of CVE-2019-1698, a WordPress plugin SQL injection vulnerability, with code diff review, vulnerable function…

Proof-of-concept for CVE-2021-44906 demonstrating prototype pollution in minimist via Function.prototype bypass, with runnable examples and detailed…

https://nvd.nist.gov/vuln/detail/CVE-2022-34169

Docker-based lab to reproduce CVE-2017-9841, a remote code execution vulnerability in PHPUnit's eval-stdin.php when installed under a web root.



Static analysis tool to detect homoglyph substitution attacks in source code, scanning Python identifiers for visually similar Unicode characters to…

Vulnearability Report of the New Jersey official site

Vulnearability Report of the New Jersey official site

A simple simulation of the infamous CVE-2021-44228 issue.

Fix prototype pollution vulnerability (CVE-2023-26136) for tough-cookie package

This repository serves as the public reference for CVE-2024-40445 and CVE-2024-40446. Both vulnerabilities impact MimeTeX, an open-source software…

Little recap of the log4j2 remote code execution (CVE-2021-44228)