

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

Stored XSS via Location Title in DPCalendar Free

This technical research and review is for educational purposes on public code and constitutes Fair Dealing under the Copyright Act (Canada).

Automated PoC script for CVE-2023-36845, exploiting a PHP flaw in Juniper Junos OS J-Web to remotely modify PHPRC and achieve code injection on…

Python source code auditing and static analysis on a large scale

Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

Java library providing technical commons for XWiki projects, with a focus on vulnerability analysis and static code inspection for security testing.

Download Plugin <= 2.2.8 - Authenticated (Administrator+) Arbitrary File Upload

Migration,Backup, Staging – WPvivid <= 0.9.112 - Authenticated (Admin+) Arbitrary File Upload via wpvivid_upload_file

Instantio - Wordpress Plugin <= 3.3.16 - Authenticated (Admin+) Arbitrary File Upload via ins_options_save

The code of VulTriage: Triple-Path Context Augmentation for LLM-Based Vulnerability Detection

Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass…

Proof-of-concept exploit for CVE-2025-24813, achieving remote code execution on Apache Tomcat via session deserialization and partial PUT requests.

Java utility library with a focus on a specific CVE vulnerability, providing code analysis and static analysis capabilities for security assessment.

Code review analysis for CVE-2023-4762, focusing on identifying and understanding the vulnerability through source code inspection.

Interactive program analysis suite using Code Property Graphs to hunt for bugs in C and C++ code, unifying application-specific and low-level…