
mininode
Static analysis CLI tool that reduces Node.js application attack surface by constructing dependency graphs and removing unused modules and functions…

Static analysis CLI tool that reduces Node.js application attack surface by constructing dependency graphs and removing unused modules and functions…

Semantic-aware SAST scanner for Node.js applications that detects insecure code patterns using libsast pattern matching and semgrep syntax-aware…


Example application, vulnerable to CVE-2023-32692 (Validation Rule Injection in the PHP Framework CodeIgniter)

OS Command Injection Vulnerability via Plugin Execution in Figma Desktop Application

Cross-Site Scripting (XSS) Vulnerability in Fiora Chat Application

Grails sample application using the Javamelody 1.44 plugin to illustrate the CVE-2013-4378 vulnerability.

Demonstrates exploitation of CVE-2017-8046 in a Spring Boot application, including a SpEL injection payload and dependency-check verification for…

Advisory: CVE-2026-38360 path traversal (CWE-22) in dash-uploader (Python/PyPI)

Demo app showing how the Rails CVE-2013-5664 vulnerability works.

CVE-2026-34038: Authenticated Remote Command Injection in Coolify

I couldn’t find a PoC for CVE-2023-30253, so I developed an effective one


Jenkins plugin providing Git APIs for automated repository operations including fetch, checkout, merge, and tag, with support for credential-based…

Proof-of-concept exploit for CVE-2020-5245, demonstrating expression language injection in Dropwizard REST endpoints via crafted HTTP parameters.

Exploit for the Rails CVE-2019-5420

Showcase of overridding the Spring Framework version in older Spring Boot versions

Educational analysis and proof-of-concept exploit for CVE-2022-22965, a Spring MVC/WebFlux remote code execution vulnerability via data binding on…