


CVE-2026-0006: Heap buffer overflow PoC for libopenapv (Android APV codec) - CVSS 9.8

Proof-of-concept exploit for CVE-2026-33154, demonstrating remote code execution via SSTI in Dynaconf's Jinja resolver, with analysis and mitigation…

PoC and analysis for Kibana Prototype Pollution RCE (CVE-2019-7609).

Multi-agent static application-security review harness for AI coding agents: maps codebases, hunts vulnerability classes, chains and verifies…

Automated secret and leak detection scanner for GitHub and paste sites, with heuristic filtering, IOL enrichment via Shhgit/TruffleHog, and ELK-based…

AI red-team platform. Autonomous LLM agents run a penetration test end to end inside a Kali container and write the report. LangGraph plan/act…

Reproducer for CVE-2026-40047: Apache Camel camel-docling CLI argument injection / path traversal

Plugin for JADX to integrate MCP server

A tool to capture all the git secrets by leveraging multiple open source git searching tools

Deliberately vulnerable Java/Maven fixture for testing Log4Shell (CVE-2021-44228) detection, code-impact classification, and remediation guidance in…

Proof-of-concept exploit and lab environment for CVE-2026-27495

ecurity patch for CVE-2023-26136 in tough-cookie 2.5.0 - Prototype pollution vulnerability fix with backward compatibility


Docker-based lab environment for CVE-2015-1427 ElasticSearch Groovy sandbox bypass and remote code execution, demonstrating two POC methods with Java…

Authenticated Remote Code Execution via loadReader functionName code injection in DbGate

CVE-2022-31626, CVE-2024-2961, CVE-2019-6977, PHP security research

Ghidra is a software reverse engineering (SRE) framework