
reactguard
ReactGuard provides framework- and vulnerability-detection tooling for CVE-2025-55182 (React2Shell)

ReactGuard provides framework- and vulnerability-detection tooling for CVE-2025-55182 (React2Shell)

Example exploitable scenarios for CVE-2024-22243 affecting the Spring framework (open redirect & SSRF).

Cursor plugin for Hono v4 (TypeScript edge web framework). 59 LLM regressions with BAD/CORRECT pairs. Pinned to hono ^4.12.19 (>= 4.9.7 for…

Proof-of-concept exploit for CVE-2022-22965 (Spring4Shell) targeting Java Spring Framework applications via crafted HTTP requests.

Exploit for CVE-2023-40133, a vulnerability in Android's Framework component, enabling code execution analysis and security testing.

Detection scripts and guidance for CVE-2022-22965 (Spring4Shell) vulnerability in Spring Framework, including PowerShell and Bash scanners for…

Proof-of-concept exploit for CVE-2022-27772 targeting Grails 3.3 framework's custom TomcatEmbeddedServletContainerFactory, demonstrating insecure…

Frida-based .NET Framework injector and managed method hooking toolkit for runtime tracing, native entrypoint resolution, and dynamic analysis of…

Android platform framework repository containing a patch or analysis for CVE-2023-21288, a vulnerability in the Android framework.

Exploit for Apache Struts CVE-2017-9805, a remote code execution vulnerability in the REST plugin. Enables penetration testing and security…

The code of VulTriage: Triple-Path Context Augmentation for LLM-Based Vulnerability Detection

Proof-of-concept exploit for CVE-2024-38820, demonstrating locale-dependent case conversion bypass of Spring Framework DataBinder disallowedFields…

Spring Framework RCE exploit (CVE-2022-22965) with analysis code and educational walkthrough for understanding the vulnerability and exploitation…

Modular framework to detect and prevent dependency confusion attacks by analyzing package manifests across multiple sources and package management…

Proof-of-concept exploit for CVE-2025-51482, demonstrating remote code execution via unsafe exec() usage and sandbox bypass in the Letta AI agent…

Exploit for CVE-2011-4367 targeting Apache MyFaces JSF implementation, demonstrating a remote code execution vulnerability in the Jakarta Faces…

Static Analyzer for Solidity and Vyper

Static Analyzer for Starknet smart contracts