
bassmaster-rce
Exploiting CVE-2014-7205 by injecting arbitrary JavaScript resulting in Remote Code Execution.

Exploiting CVE-2014-7205 by injecting arbitrary JavaScript resulting in Remote Code Execution.

Cursor plugin for Hono v4 (TypeScript edge web framework). 59 LLM regressions with BAD/CORRECT pairs. Pinned to hono ^4.12.19 (>= 4.9.7 for…

Security Advisory: Camaleon CMS - Authenticated RCE via `select_eval` Custom Field

Senior-CSO security audit skill for vibe-coded apps. 22-check audit anchored to real 2026 incidents (Moltbook, Lovable CVE-2025-48757). Drop-in…

WordPress wp2shell pre-auth RCE exploit kit (CVE-2026-63030 + CVE-2026-60137)

Detect CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Fast, accurate scanner with zero false positives.

Proof-of-concept demonstrating arbitrary command execution via malicious virtual environment activation scripts in PyCharm before 2020.3.4,…

Confluence unauthorize template injection

PoC reproducer for CVE-2026-49042 (Apache Camel camel-langchain4j-tools): a prompt-injected LLM's tool-call arguments become unfiltered Exchange…

Unauthenticated Local File Inclusion

Proof-of-concept exploit for unauthenticated remote code execution in pfBlockerNg via unsanitized input in the DNSBL TLD query function, with SAST…

Consul Template validated where a symlink pointed during template evaluation, but its later dependency fetch read the original path. Retargeting the…

Example application, vulnerable to CVE-2023-32692 (Validation Rule Injection in the PHP Framework CodeIgniter)

CVE-2026-11837: local privilege escalation in the ansible.posix authorized_key module via symlink-following chown. Technical writeup; sibling of…

This is N-day patch we releasing by testing our model capabilities

CVE-2026-25541 impact analysis for Fuel infrastructure (bytes crate integer overflow)

Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE

Exploit for CVE-2023-27372 with interactiev shell