
yari
YARI is an interactive debugger for YARA Language.

YARI is an interactive debugger for YARA Language.

RCE exploit toolkit for CVE-2025-55182 and CVE-2025-66478 in React Server Components. Includes multiple exploit variants, detection scripts, a…

Proof-of-concept exploit for CVE-2026-34197, demonstrating authenticated remote code execution in Apache ActiveMQ via Jolokia JMX-HTTP bridge and…

CVE-2026-2587 PoC validator for Eclipse GlassFish EL Injection RCE in the admin console gadget.jsf handler. Safe authenticated vulnerability scanner…

Intentionally vulnerable Next.js corporate landing page demonstrating CVE-2025-55182, a JSON injection leading to RCE/SSRF via unsafe deserialization…

Edge-coverage-guided fuzzer for PHP libraries that detects bugs via crashes, timeouts, and warnings. Supports corpus management, crash minimization,…

Externalize Java application access to protected resources as log messages.

CVE-2026-53753 — Crawl4AI <0.8.7 unauthenticated RCE (AST sandbox escape via gi_frame.f_back). Lab + PoC, verified e2e.

Detection for CVE-2025-4427 and CVE-2025-4428

Java library for XML serialization and deserialization, with a focus on the CVE-2020-26217 deserialization vulnerability exploit.

Isolated JavaScript sandbox for Node.js that runs untrusted code with restricted access to built-in modules and host resources via Proxy-based…

Rust macros and Cargo subcommand to automate fuzzing with afl.rs, including corpus generation and harness implementation, integrated with Rust's…

a fast check, if your server could be vulnerable to CVE-2021-44228

LittleCorporal: A C# Automated Maldoc Generator

Coverage-based fuzzer for python applications

Jackson Rce For CVE-2019-12384

Working proof of concept for NextJS RCE to establish a reverse shell. [React2Shell]

The OWASP Benchmark GitHub repo has moved to: https://github.com/OWASP-Benchmark/BenchmarkJava