
Curveball
PoC for CVE-2020-0601 - CryptoAPI exploit

PoC for CVE-2020-0601 - CryptoAPI exploit

CVE-2023-46818 Python3 Exploit for ISPConfig <= 3.2.11 (language_edit.php) PHP Code Injection Vulnerability

GiveWP PHP Object Injection exploit

The vibe-coding security sentinel. Apache-2.0 agentic security toolkit for AI-assisted projects: 5 deterministic scouts + LLM Brain Layer (BYOK…

Rule-based linter for OpenSSH client config files that detects duplicate hosts, missing identity files, weak algorithms, wildcard ordering issues,…

Managing GitHub Advanced Security (GHAS) Controls at Scale

SnakeYAML-CVE-2022-1471-POC

CVE-2026-20251 — Splunk Secure Gateway jsonpickle deserialization RCE (CVSS 8.8) | ReactiveZero Security Research


Exploiting CVE-2022-0847 - written by : Antonius (w1sdom)

The code for personally reproducing the corresponding vulnerability

CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).

Proof-of-concept exploit and lab environment for CVE-2026-27495

CVE-2026-58138 — Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator (HostAccess.ALL). Lab + PoC, verified e2e (root).


Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass…