
CVE-2024-9593
Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code Execution

Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code Execution

A prompt injection in a code‑review bot that executes AI‑generated fixes in a sandbox. The sandbox uses a blacklist to prevent dangerous commands,…

The code of VulTriage: Triple-Path Context Augmentation for LLM-Based Vulnerability Detection

CVE-2018-7600 Drupal Drupalgeddon 2 远程代码执行漏洞利用脚本

Proof-of-concept exploit for CVE-2026-19626, an authenticated remote code execution in SecurityCenter report generation, demonstrating a non-admin…

CVE-2026-67598 — Emlog Pro: disabled TLS certificate validation in AI assistant (MITM → API-key theft). CWE-295, CVSS 9.1. Reported by @IlhomjonR.

Proof-of-concept exploit for CVE-2023-49314 demonstrating code injection in Asana Desktop on macOS via Electron Fuses, with automated vulnerability…

Silent dependency injection through AI documentation pipelines. 240 isolated Docker runs proving Context Hub's zero-sanitization MCP server lets…

Nuclei template to detect CVE-2025-24016 unsafe deserialization RCE in Wazuh servers via a crafted JSON payload that triggers a NameError.

Research repository documenting LLM generalization ceilings in code security vulnerability detection, with cross-evaluation across synthetic and…

Python-based RCE exploit for CVE-2026-42588 targeting Apache ActiveMQ Jolokia. Features check-only mode, malicious XML generation, and support for…

A testing framework to identify and demonstrate deserialization vulnerabilities in LangChain Core (<0.3.81). Educational use only

Static analysis CLI that scans codebases for LLM prompt-injection, data-exfiltration, jailbreak, and unsafe agent/tool vulnerabilities. Runs fully…

Code for ACL 2026 (main) paper "DeepGuard: Secure Code Generation via Multi-Layer Semantic Aggregation"

An Evaluation Agent for Detecting Misinformation and Knowledge Poisoning in Retrieval-Augmented Generation Systems.

Two-stage prompt-injection and jailbreak detector: regex gates plus a quantised DeBERTa-v3 ONNX classifier, with image, document, and audio support.…

Orbit Tracer Security Agent for intelligent security remediation. Traces vulnerability blast radius using Orbit's knowledge graph, scores risk,…

Scan a repo's .claude/ config (settings.json hooks, MCP servers, env, allowed-tools) for the RCE & API-key-exfiltration footguns (CVE-2025-59536,…