
cargo-perm
Cargo exploit from CVE-2023-38497

Cargo exploit from CVE-2023-38497

Authenticated low-privileged RCE in Coolify via unsanitized shell commands in the Git Repository field.

CVE-2020-26259 &&XStream Arbitrary File Delete

Proof-of-concept (PoC) exploit for JSONPath-plus vulnerability


CVE-2025-13486 - Remote Code Execution & Privilege Escalation exploit

Scan a repo for AI-IDE config files that can trigger RCE via Claude Code hooks, Cursor rules, MCP auto-registration. Detects CVE-2025-59536,…

Drop-in WordPress plugin that blocks the vulnerable Demo Import handler in FunnelForms Pro to mitigate Remote Code Execution (CVE-2026-39440).

Are you get Tanstack Supply chain attack attack of 5/11? CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx

Analyzes a specific CVE in WeChat OAuth handler, identifying unbounded HTTP response reads leading to denial of service, with remediation guidance.

Apache synapse 反序列化 CVE–2017–15708

Detect-only scanner for CVE-2026-42945 (NGINX Rift), a heap overflow in ngx_http_rewrite_module. Version detection + nginx.conf pattern analysis.…

CVE-2026-23498 - Shopware Has Improper Control of Generation of Code in Twig rendered views

Demo consumer for gin v1.7.0 (CVE-2023-29401) — Context.FileAttachment with user input. endorctl scan target.

A writeup investigating the full extent of CVE-2019-25137

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

A security-patched fork of the legacy ClickFunnels Classic WordPress plugin. Fixes critical Stored XSS vulnerabilities (CVE-2022-4782) while…

Professional Service scripts to aid in the identification of affected Java applications in TeamServer