
CVE-2026-48017
Remote Code Execution in DbGate via functionName injection in the loadReader endpoint — CVSS 8.8

Remote Code Execution in DbGate via functionName injection in the loadReader endpoint — CVSS 8.8
PoC — path traversal via unsanitized LLM-derived domain field in OpenLore (GHSA-5j8x-q7q6-58j5, CVE-2026-87001, CVSS 4.7).

Buildless dependency auditor that scans 10 ecosystems offline, reporting CVEs prioritized by CISA KEV and EPSS, EOL packages, licenses, committed…

AI Prompt Secret Scanner: local proxy and Claude Code hook that blocks secrets before they reach AI APIs

CVE-2024-0195 Improper Control of Generation of Code ('Code Injection')

Detection for CVE-2025-53690

Jenkins POC of Arbitrary file read vulnerability through the CLI can lead to RCE

This is a Python Application that helps you detect if your machine that run bash is vulnerable by CVE-2014-6271

Educational analysis and proof-of-concept exploit for CVE-2025-3248, a critical unauthenticated code injection vulnerability in Langflow, including…

Critical use-after-free vulnerability discovered in Tinyproxy

Scan codebases for quantum-vulnerable cryptography. Detect RSA, ECDSA, Ed25519, ECDH before Q-Day. CycloneDX CBOM + SARIF output.

A testing framework to identify and demonstrate deserialization vulnerabilities in LangChain Core (<0.3.81). Educational use only

Black-box WordPress vulnerability scanner that detects security issues, enumerates users, brute-forces logins via XMLRPC, and performs static PHP…

7-Zip XZ Decoder Heap Buffer Overflow - Full analysis, root cause, PoC, and RCE exploitation roadmap

PoC: identify silent security patches before CVE

CVE Reproduction: cve-2024-50330-ivanti_epm_sqli_reproduction

Async RCE scanner for CVE-2025-55182 / CVE-2025-66478 — prototype-pollution → code execution via React Server Actions.

BlockChain Security Construction