
NovaLdr
Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)

Threadless Module Stomping In Rust with some features (In memory of those murdered in the Nova party massacre)

Self-contained Docker lab demonstrating CVE-2007-4559 (TarSlip) directory traversal via Python's tarfile module. Includes vulnerable and fixed APIs,…

Proof-of-concept demonstrating CVE-2007-4559 path traversal in Python's tarfile module, allowing arbitrary file overwrite via malicious TAR archives.

CodeQL query test for CVE-2023-24329, demonstrating static analysis detection of a specific vulnerability in Python's urllib.parse module.

Build and query a graph database representation of source code

Major Security Vulnerability on PrestaShop Websites - CVE-2022-31101

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

Code execution/injection technique using DLL PEB module structure manipulation

Proof-of-concept exploit module for CVE-2019-11043 (PHP-FPM remote code execution) with batch scanning capabilities for vulnerable Nginx…

"In-depth reverse engineering analysis of an advanced multi-phase loader targeting Shellhost.exe, amsi.dll, mstscax.dll, and clbcatq.dll using module…

PoC repository for CVE-2025-68147: Stored Cross-Site Scripting (XSS) in OpenSourcePOS. Vulnerability allows privilege escalation via malicious…

Module for PrestaShop 1.7.X to fix CVE-2023-28447 vulnerability (Smarty XSS)

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest! https://snuffleupagus.rtfd.io

Proof-of-concept exploit for CVE-2026-22686, demonstrating remote code execution in Node.js ESM sandboxes via process.getBuiltinModule to bypass…

PHP-based exploit module targeting CVE-2025-67146 and CVE-2025-67147 for automated vulnerability exploitation and security assessment.

CVE-2026-11837: local privilege escalation in the ansible.posix authorized_key module via symlink-following chown. Technical writeup; sibling of…

Proof-of-concept exploit for CVE-2024-21534, a critical RCE in jsonpath-plus, demonstrating arbitrary code execution via the VM module and providing…

CVE-2023-50029: PHP Injection Vulnerability in M4 PDF Extensions Module