
CVE-2023-0297_Pre-auth_RCE_in_pyLoad
CVE-2023-0297: The Story of Finding Pre-auth RCE in pyLoad

CVE-2023-0297: The Story of Finding Pre-auth RCE in pyLoad

Proof of Concept for the Apache commons-text vulnerability CVE-2022-42889.

CVE-2020-35728 & Jackson-databind RCE

Self-hosted multi-agent environment for Go with LLM-powered pentesting agents (exploiter, reverser, threathunter, webscanner) that automate…

Proof-of-concept exploit for CVE-2026-48909: unauthenticated remote code execution via PHP object injection in JoomShaper SP LMS. Includes detection,…

Source code for the Binaries of OWASP WrongSecrets

Shields against supply-chain, slopsquatting, and typosquatting attacks from dependencies and code.

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

Generate malicious files using recently published homoglyphic-attack (CVE-2021-42694)

Demonstrating that SSLVerifySignedServerKeyExchange() is trivially testable.

Intentionally vulnerable Next.js application demonstrating CVE-2025-55182 RCE via unsafe deserialization in React Server Components. Includes exploit…

Static analysis CLI tool that reduces Node.js application attack surface by constructing dependency graphs and removing unused modules and functions…

This repository contains a proof-of-concept exploit script for CVE-2025-32432, a pre-authentication Remote Code Execution (RCE) vulnerability…

This repository contains a POC of CVE-2025-55182, a critical (CVSS score 10.0) pre-authentication remote code execution vulnerability affecting React…

CVE-2022-22965 - CVE-2010-1622 redux

Dockerized PoC environment for CVE-2022-22980 (Spring Data MongoDB SpEL injection) with a working exploit demonstrating remote code execution via…