
spring-projects__spring-framework_CVE-2022-22965_5-2-19-RELEASE
Exploit for CVE-2022-22965 (Spring4Shell) targeting Spring Framework versions vulnerable to remote code execution via classLoader manipulation.

Exploit for CVE-2022-22965 (Spring4Shell) targeting Spring Framework versions vulnerable to remote code execution via classLoader manipulation.

Exploit for Apache Struts CVE-2017-9805, a remote code execution vulnerability in the REST plugin. Enables penetration testing and security…


The Secure Coding Framework

Example exploitable scenarios for CVE-2024-22243 affecting the Spring framework (open redirect & SSRF).

Example application, vulnerable to CVE-2023-32692 (Validation Rule Injection in the PHP Framework CodeIgniter)

Android platform framework patch for CVE-2023-21281, addressing a security vulnerability in the Android framework.

Android platform framework repository containing a patch or analysis for CVE-2023-21288, a vulnerability in the Android framework.

Showcase of overridding the Spring Framework version in older Spring Boot versions

Security-focused static analysis for the Phoenix Framework

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

Proof-of-concept exploit for CVE-2022-27772 targeting Grails 3.3 framework's custom TomcatEmbeddedServletContainerFactory, demonstrating insecure…

A complete framework for exploiting the vulnerability CVE-2025-55182

Vulnerability Assessment and Auditing Framework for all the Crypto Implementations.

Exploit for CVE-2011-4367 targeting Apache MyFaces JSF implementation, demonstrating a remote code execution vulnerability in the Jakarta Faces…

Spring4Shell is a critical RCE vulnerability in the Java Spring Framework and is one of three related vulnerabilities published on March 30

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

Static code analysis tool for Android apps based on OWASP MASVS, detecting security vulnerabilities in APK files with low false-positive rates and…