
CVE-2025-60374
CVE-2025-60374: Stored Cross-Site Scripting (XSS) in Perfex CRM Chatbot

CVE-2025-60374: Stored Cross-Site Scripting (XSS) in Perfex CRM Chatbot

Asset-wide detection tool for identifying jsPDF usage related to CVE-2025-68428 Detection only — no exploitation

Disclosure for CVE-2025-13339

Network-based vulnerability scanner for detecting systems vulnerable to CVE-2025-53770 (unsafe deserialization). Includes PowerShell and Python…

Python exploit script for CVE-2025-2294, an unauthenticated Local File Inclusion vulnerability in WordPress Kubio AI Page Builder ≤ 2.5.1. Supports…

Patch for CVE-2018-1000140 in rsyslog's librelp library, fixing a remote code execution vulnerability in the reliable event logging protocol…

Full-featured open-source toolkit implementing SSL/TLS protocols and a general-purpose cryptography library, including ciphers, digests, public key…

Java library that converts malformed JSON-like content into standards-compliant, safe JSON, preventing code injection and ensuring embeddability in…

Proof-of-concept for CVE-2024-43018: SQL injection in Piwigo 13.8.0 via unsanitized max_level and min_register parameters, enabling information…

OpenSSL 1.1.0g cryptographic library and TLS toolkit, providing encryption, decryption, certificate management, and SSL/TLS protocol support for…

Anticipator is an open-source threat detection platform for multi-agent AI systems.

glibc getaddrinfo stack-based buffer overflow

Proof-of-concept exploit for CVE-2024-6387, a remote code execution vulnerability in OpenSSH server, demonstrating exploitation techniques for…

CVE-2022-22947 exploit script

Proof-of-concept exploit for CVE-2024-0195, a critical code injection vulnerability in SpiderFlow 0.4.3 enabling remote code execution via the…

JSON sanitizer that converts malformed JSON-like content into valid, safe JSON, preventing code injection and ensuring standards compliance for web…

[Moved to Codeberg] Simple local scanner for vulnerable log4j instances

Proof-of-concept exploit for authenticated OS command injection (CWE-78) in Cacti ≤1.2.30, achieving remote code execution with CVSS 7.2.