
log4j2-rce-recap
Little recap of the log4j2 remote code execution (CVE-2021-44228)

Little recap of the log4j2 remote code execution (CVE-2021-44228)
Docker-based lab to reproduce CVE-2017-9841, a remote code execution vulnerability in PHPUnit's eval-stdin.php when installed under a web root.

Curated Java web framework vulnerability (CVE-2016-5394) for Apache Sling, designed for security testing, exploitation practice, and vulnerability…

A generative test that would've caught CVE-2020-28052

An attempt to understand the log4j vulnerability by looking through the code

jee web project with sanitised log4shell (CVE-2021-44228) vulnerability

Secure coding project, research on CVE-2019-17498 and implement a player score function written in C.

Fix open source package uses tough-cookie 2.5.0 - CVE-2023-26136,


Implementações de servidores HTML em GO para análise da vulnerabilidade CVE-2023-29406.

Demonstrates CVE-2015-10034 in a vulnerable Java application, including SARIF analysis results from J-TAS Action for educational security testing.

Reproducible CVE-2015-6748 vulnerability example in jsoup HTML parser, demonstrating XSS prevention bypass and DOM-based parsing flaws for security…

simple application with a (unreachable!) CVE-2022-45688 vulnerability

simple application with a (unreachable!) CVE-2022-45688 vulnerability

Educational repository demonstrating XSS vulnerabilities in Django Rest Framework applications. Contains intentionally vulnerable code to teach…

Generic rendering system converting wiki syntax, HTML, and other formats into XHTML. Part of the XWiki platform, providing a flexible and extensible…

Type-safe Java Mustache templating engine with compile-time template validation, static value binding, and extensible escaping for HTML and other…

Minimal reproduction of CVE-2022-46175 demonstrating a JSON5 prototype pollution vulnerability in Quasar webpack projects for security education and…