


Generate malicious files using recently published bidi-attack (CVE-2021-42574)

Output high level Pcode (PcodeAST) in Ghidra

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

Collection of some easy of use tools - in powershell.

Managing GitHub Advanced Security (GHAS) Controls at Scale

The OWASP Benchmark GitHub repo has moved to: https://github.com/OWASP-Benchmark/BenchmarkJava

Prevent PHP vulnerabilities similar to CVE-2016-10033 and CVE-2016-10045.

Imagemagick CVE-2022-44268

C# source-code obfuscator that replaces character and string literals with emojis and randomizes class, interface, method, and variable names using…

CVE-2019-12814:Jackson JDOM XSLTransformer Gadget

Test wether you're exposed to ghost (CVE-2015-0235). All kudos go to Qualys Security

PoC — symlink following to out-of-repo content disclosure via search_text in Gortex (GHSA-6vhf-4wcm-2r83, CVE-2026-87003, CVSS 5.5).

CVE-2020-10673:jackson-databind RCE

CVE-2022-1292 OpenSSL c_rehash Vulnerability

Static analysis of 2 malicious Office documents on REMnux using oletools; identified CVE-2017-11882 and obfuscated macros.

CVE-2020-11113:Jackson-databind RCE

Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass…