
OpenSSL-1_0_1g_CVE-2015-3194
OpenSSL 1.0.1g source code snapshot, providing SSL/TLS and general-purpose cryptographic library with ciphers, digests, and X.509 certificate…

OpenSSL 1.0.1g source code snapshot, providing SSL/TLS and general-purpose cryptographic library with ciphers, digests, and X.509 certificate…

Running OWASP cve-lite-cli against the pi monorepo: scan journey and key finding (vitest CVE-2026-47429).

Detection scripts for CVE-2023-50164 in Apache Struts2, providing PowerShell and Bash tools to scan for vulnerable versions across file systems and…

Proof of Concept for CVE-2023-40296

Tainacan <= 0.21.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read

CImg Library v.2.3.3 - command injection

Proof-of-Concept for CVE-2025-55182, a critical unauthenticated RCE in React Server Components.

Asset-wide detection tool for identifying jsPDF usage related to CVE-2025-68428 Detection only — no exploitation

This technical research and review is for educational purposes on public code and constitutes Fair Dealing under the Copyright Act (Canada).

Authenticated remote code execution exploit for Roundcube Webmail (CVE-2025-49113) via insecure deserialization. Includes session injection, gadget…

Proof-of-concept exploit for Jenkins Templating Engine plugin sandbox bypass (CVE-2025-31722) enabling remote code execution via malicious Groovy…

CVE-2026-25747 - Camel LevelDB Deserialization Vulnerability


Researching on the vulnrability CVE-2023-26136

nltk.tokenize.StanfordSegmenter dynamically loads external Java .jar files without verification or sandboxing. If an attacker can supply or replace…

Disclosure for CVE-2025-13339

CVE-2025-60374: Stored Cross-Site Scripting (XSS) in Perfex CRM Chatbot

Exploit for CVE-2023-27372 with interactiev shell