
Veridiff
Dynamic branch-divergence finder for native code -- traces two Frida executions and finds the exact instruction where they diverge.

Dynamic branch-divergence finder for native code -- traces two Frida executions and finds the exact instruction where they diverge.

Demo environment for CVE-2022-22980 (Spring Data MongoDB SpEL injection RCE) with vulnerable application code for security testing and education.

Python tool for safe archive handling, path traversal awareness, and secure extraction. Inspired by CVE-2025-8088.

Code for veracode blog

Camaleon CMS v2.7.0 contain a Server-Side Template Injection (SSTI) vulnerability

Magento Unauthorized Remote Code Execution (CVE-2016-4010)

Proof-of-concept emulation and analysis of CVE-2025-1094, a critical PostgreSQL SQL injection vulnerability. Includes Docker-based lab setup, exploit…

spring data mongodb remote code execution | cve-2022-22980 poc

Proof-of-concept exploit for CVE-2024-50340 demonstrating Symfony ArgvInput environment variable injection via crafted URL query parameters, enabling…

Proof-of-concept demonstration for CVE-2020-28948 and CVE-2020-28949, PHP Archive_Tar path traversal and arbitrary file write vulnerabilities.

Scanner for CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) - Track and remediate a critical React Server Components (RSC) / Flight protocol…

WordPress Verification SMS with TargetSMS Plugin <= 1.5 is vulnerable to Remote Code Execution (RCE)

Checkov PoC: arbitrary code execution through auto-loaded configuration and unsigned external Python checks.

PoC: identify silent security patches before CVE

Proof of Concept exploitation of CVE-2026-5760 - RCE in SGLang 0.5.9 via malicious GGUF

PoC — frontmatter-driven arbitrary JavaScript execution in Note Toolbar for Obsidian (GHSA-q8cw-3m8c-5pf2, CVE-2026-87002, CVSS 7.0).

A comprehensive browser extension (.xpi) malware scanner which checks for many common malware tricks like:, credential-stealers obfuscation tactics,…

A bit of research around CVE-2024-52301