
Bughound
Static code analysis tool based on Elasticsearch

Static code analysis tool based on Elasticsearch

Vulnearability Report of the New Jersey official site

Researching on the vulnrability CVE-2023-26136

This repository contains a solution for the CVE-2023-26136 vulnerability.

Details about the Blind RCE issue(SPX-GC) in SPX-GC

Vulnearability Report of the New Jersey official site

Proof-of-concept exploit for an arbitrary file write vulnerability in Halo CMS backup restoration, enabling RCE via plugin JAR replacement or…

Go-based automation tool that scans GitHub repositories for vulnerable Next.js versions (CVE-2025-66478) and automatically creates pull requests with…

OpenSSF Scorecard - Security health metrics for Open Source

A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to…

Jenkins POC of Arbitrary file read vulnerability through the CLI can lead to RCE

The WP Booking Calendar plugin for WordPress is vulnerable to SQL Injection via the 'calendar_request_params[dates_ddmmyy_csv]' parameter in all…

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

CurveBall (CVE-2020-0601) - PoC CVE-2020-0601, or commonly referred to as CurveBall, is a vulnerability in which the signature of certificates using…

Resources related to GitHub Security Lab

PoC for CVE-2020-0601- Windows CryptoAPI (Crypt32.dll)

Exploit for Grafana arbitrary file-read and RCE (CVE-2024-9264)