
CVE-2020-36184
CVE-2020-36184 && Jackson-databind RCE

CVE-2020-36184 && Jackson-databind RCE

Example exploitable scenarios for CVE-2024-22243 affecting the Spring framework (open redirect & SSRF).

Security research and proof-of-concept for CVE-2026-0776 affecting Discord Desktop Client.

Multi-Ecosystem Malicious Package Detection and Supply Chain Security Scanner

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

Benchmark measuring AI models' ability to detect vulnerabilities in source code via real bug bounty cases with balanced recall and false-positive…

A complete framework for exploiting the vulnerability CVE-2025-55182

Detailed analysis and exploit for CVE-2022-22947, a remote code execution vulnerability in Spring Cloud Gateway via SpEL injection in the Actuator…

React2Shell CVE-2025-55182: unauthenticated unsafe deserialization in React Server Components leading to reliable remote code execution via the…

Demonstrates exploitation of CVE-2018-11235, a Git submodule RCE vulnerability, with build script and analysis for educational purposes.


The code of VulTriage: Triple-Path Context Augmentation for LLM-Based Vulnerability Detection

A CodeQL workshop covering CVE-2021-21380


PoC for CVE-2026-12191

Proof-of-concept exploit for CVE-2025-3248, a remote code injection vulnerability in Langflow prior to 1.3.0. Sends crafted HTTP requests to execute…

First publicly shared exploit implementation for CVE-2026-33439 (OpenAM pre-auth RCE via jato.clientSession deserialization).

CVE-2020-36188 &&Jackson-databind RCE