
CVE-2025-48384
Breaking git with a carriage return and cloning RCE

Breaking git with a carriage return and cloning RCE

Code canaries to quickly triage hallucinated ('slop') vulnerability reports

Zyrox: LLVM based, compile-time obfuscator plugin.

A JavaScript Obfuscator based on Cryptographic Indistinguishability Obfuscation techniques

Curated Semgrep rule repository for GitLab SAST, providing static analysis patterns to detect security vulnerabilities across multiple programming…

Template Injection in Email Templates leads to code execution on Jira Service Management Server

GiveWP PHP Object Injection exploit

h2-jdbc(https://github.com/h2database/h2database/issues/3195) & mysql-jdbc(CVE-2021-2471) SQLXML XXE vulnerability reproduction.

CVE-2020-36179~82 Jackson-databind SSRF&RCE

Staged static taint analysis framework for GitHub Actions workflows. Detects code injection vulnerabilities using taint-tracking and an impact…

Proof-of-concept exploit for CVE-2023-29007, a Git arbitrary configuration injection vulnerability. Demonstrates exploitation via crafted repository…

Small example repo for looking into log4j CVE-2021-44228

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

Finding vulnerabilities through dumb brute force

All-in-one macOS binary analysis: Mach-O parsing, ARM64 disassembly, code signatures, and debugging.

PoC exploit for CVE-2020-8840: JNDI injection leading to remote code execution in FasterXML jackson-databind. Includes environment setup, exploit…

Spring Cloud Netflix Hystrix Dashboard template resolution vulnerability CVE-2021-22053

Apache Karaf XXE Vulnerability (CVE-2018-11788)