
CVE-2020-0601
PoC for CVE-2020-0601- Windows CryptoAPI (Crypt32.dll) POC: https://github.com/ollypwn/CurveBall

PoC for CVE-2020-0601- Windows CryptoAPI (Crypt32.dll) POC: https://github.com/ollypwn/CurveBall

The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from…

Jackson Deserialization CVE-2017-7525 PoC

Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion

Layer-2 supply-chain hardening for MCP servers — Ed25519-signed tool manifests, runtime spawn-attestation, default-deny argument sanitizer. Defends…


Proof-of-concept exploit for CVE-2026-22686, demonstrating remote code execution in Node.js ESM sandboxes via process.getBuiltinModule to bypass…


Apache CXF SSRF CVE-2024-28752

Check the conditions for exploiting CVE-2021-23383 through the handlebars library version assessment.


A Powrshell script to scan for CVE-2021-34470

Demo app showing how the Rails CVE-2013-5664 vulnerability works.

The code for personally reproducing the corresponding vulnerability

Laravel Reverb 为 Laravel 应用提供实时 WebSocket 通信后端。在 1.6.3 及更早版本中,Reverb 将来自 Redis 通道的数据直接传递给 PHP 的 unserialize() 函数,且未对可实例化的类进行限制,导致用户面临远程代码执行风险。
