
MalEval
Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

Official code for the ISSTA 2026 paper: Is "Knowing It’s Malicious" Enough? Evaluating LLMs for Fine-Grained Malware Behavior Auditing

The code of VulTriage: Triple-Path Context Augmentation for LLM-Based Vulnerability Detection

(CVE-2017-9841) PHPUnit_eval-stdin_php Remote Code Execution

In-depth technical analysis of CVE-2022-22965 (Spring4Shell) with environment setup, debug walkthrough, and exploit chain breakdown for educational…

An Evaluation Agent for Detecting Misinformation and Knowledge Poisoning in Retrieval-Augmented Generation Systems.

Test & Analyze the CVE-2025-55182 vulnerability within Next.js Server Actions

Exploit for Apache Struts CVE-2017-9805, a remote code execution vulnerability in the REST plugin. Enables penetration testing and security…

Proof-of-concept exploit for CVE-2022-27772 targeting Grails 3.3 framework's custom TomcatEmbeddedServletContainerFactory, demonstrating insecure…

web2py/web2py @ e94946d


Spring messaging STOMP protocol RCE

Original proof-of-concept exploits for React2Shell (CVE-2025-55182), demonstrating remote code execution in Next.js applications via Webpack chunk…

WordPress wp2shell pre-auth RCE exploit kit (CVE-2026-63030 + CVE-2026-60137)

Metasploit Modules

Metasploit module that exploits a WordPress unserialization vulnerability (CVE-2024-31211) in WP_HTML_Token to achieve remote code execution.

Metasploit exploit module for CVE-2024-6366, an unauthenticated file upload remote code execution in WordPress User Profile Builder before 3.11.8,…