
java-html-sanitizer
Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

Takes third-party HTML and produces HTML that is safe to embed in your web application. Fast and easy to configure.

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…

Educational exploit demo for CVE-2018-1263 (phpMyAdmin RCE/LFI). Includes vulnerable environment setup via Docker and step-by-step attack walkthrough…

Proof-of-concept exploit for CVE-2024-24725, demonstrating a web application vulnerability with PHP-based exploitation code for security testing and…

Repository containing the DSpace 4.4 source code with a focus on CVE-2016-10726, providing a reference for vulnerability analysis and educational…

Ruby-based exploit for CVE-2020-15169, demonstrating a specific web application vulnerability with proof-of-concept code for security testing and…

Example exploitable scenarios for CVE-2024-22243 affecting the Spring framework (open redirect & SSRF).

A vulnerable version of Rails that follows the OWASP Top 10

A source code static analysis platform for AppSec enthusiasts.

CVE-2024-0195 Improper Control of Generation of Code ('Code Injection')

SQL Injection vulnerability discovered in Grocery Store Management System 1.0

Proof-of-concept exploit for CVE-2024-0195, a critical code injection vulnerability in SpiderFlow 0.4.3 enabling remote code execution via the…

Do You Know What's In Your Python Packages? A Tool for Visualizing Python Package Registry Security Audit Data

Security Advisory: HTTP Response Splitting via Unvalidated Response Header Values (rouille)

Laravel 5 POP chain exploit for CVE-2021-43503, demonstrating a personally discovered deserialization vulnerability with proof-of-concept code.

iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and…

Proof-of-concept exploit for CVE-2019-11358, a prototype pollution vulnerability in jQuery's extend method (versions <3.4.0). Demonstrates the attack…

CVE-2025-60374: Stored Cross-Site Scripting (XSS) in Perfex CRM Chatbot