
CVE-2026-10036-speechbrain-rce
SpeechBrain < 1.1.1 checkpoint metadata RCE via unsafe PyYAML parsing of CKPT.yaml.

SpeechBrain < 1.1.1 checkpoint metadata RCE via unsafe PyYAML parsing of CKPT.yaml.

Affected versions of this package are vulnerable to Prototype Pollution.


List of mixed boolean-arithmetic resources

This is a Python Application that helps you detect if your machine that run bash is vulnerable by CVE-2014-6271

Python exploit for CVE-2022-28171 targeting Hikvision Hybrid SAN devices, automating blind SQL injection and command injection to achieve remote code…

CVE-2026-56121 — Feast <0.63.0 unauthenticated RCE via gRPC registry dill.loads of OnDemandFeatureView UDF (pre-auth). Lab + PoC, verified e2e.

Detailed technical analysis of CVE-2026-47777, a high-severity authorization bypass in Mastodon's Featured Collections federation pipeline, including…

A proof of concept for Joomla's CVE-2015-8562 vulnerability

Exploit on the default cache of superset by using pickle

Security review of CVE-2024-3094 (XZ Utils backdoor) including threat modeling, static/dynamic code analysis, fuzzing with AFL++, and a…

Proof-of-concept demonstrating command injection in aws-mcp-server via shell=True, with analysis of the vulnerable code and the fix in v1.7.0.

Proof-of-concept demonstrating prototype pollution in deephas <=1.0.7 (CVE-2026-25047) leading to arbitrary code execution and denial of service,…


Scans GitHub workflows and logs for indicators of CVE-2025-30066, detecting malicious actions and exposed secrets using Checkmarx 2ms integration.

Proof of concept for XXE in Ktor (CVE-2023-45612)

A hands-on simulation of CVE-2017-5638 (Apache Struts2 RCE), showcasing exploit reproduction, OS-level command execution, and mitigations such as…

Python exploit script for CVE-2025-2294, an unauthenticated Local File Inclusion vulnerability in WordPress Kubio AI Page Builder ≤ 2.5.1. Supports…