
CVE-2021-3129
Laravel debug mode - Remote Code Execution (RCE)

Laravel debug mode - Remote Code Execution (RCE)
Patched version of Expat XML parser for AOSP10, addressing CVE-2022-25236. Provides source code for vulnerability analysis and educational review of…

Proof-of-concept exploit for CVE-2024-6387, a remote code execution vulnerability in OpenSSH server, demonstrating exploitation techniques for…

An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UChar pointer is dereferenced…

Repository dedicated to CVE-2022-25313, a vulnerability in Expat 2.1.0, providing analysis and potential exploitation code.

Proof-of-concept exploit for CVE-2024-22640, a ReDoS vulnerability in TCPDF <=6.7.4 triggered by crafted HTML color input, with demonstration code.

Heap-buffer-overflow in Oniguruma (function fetch_interval_quantifier)

C library for VP8/VP9 video encoding and decoding, with a focus on security patching for CVE-2023-5217.

C library for parsing XML, providing stream-oriented parsing with handler registration, supporting UTF-16 encoding, and including a reference manual.

Patched libvpx codebase addressing CVE-2023-5217 with sanitizer support and cross-platform build configurations for secure VP8/VP9 encoding.

A generative test that would've caught CVE-2020-28052

Reference implementation of Bean Validation 2.0 (JSR-380) providing annotation-driven metadata model and API for JavaBean and method validation with…

C library for parsing XML, patched for CVE-2022-25315, providing stream-oriented XML parsing with handlers for efficient document processing.

0-day malware detection for binaries, source & scripts (that doesn't suck)

A native APK and DEX decompiler written in Rust

An LLM-driven fuzzing pipeline powered by the GitHub Security Lab Taskflow Agent

Local-first macOS research browser built on a custom Brave build that captures network traffic, fingerprints, scripts, and runtime evidence for…