
VibeSec-Skill
This skill helps Claude write secure code and prevent common vulnerabilities.

This skill helps Claude write secure code and prevent common vulnerabilities.

The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

This is the main repository for metasm, a free assembler / disassembler / compiler written in ruby

This is an intentionally vulnerable smart contract truffle deployment aimed at allowing those interested in smart contract security to exploit a wide…

This repository contains PoC for CVE-2024-7965. This is the vulnerability in the V8 that occurs only within ARM64.

This is a filter bypass exploit that results in arbitrary file upload and remote code execution in class.upload.php <= 2.0.4

This repository contains potential security patches for the Magento APSB22-48 and CVE-2022-35698 security vulnerability

This repository contains a proof-of-concept exploit script for CVE-2025-32432, a pre-authentication Remote Code Execution (RCE) vulnerability…

We would like to request that all contributors please clone a *fresh copy* of this repository since the September 21st maintenance.

This repository contains a POC of CVE-2025-55182, a critical (CVSS score 10.0) pre-authentication remote code execution vulnerability affecting React…

This repo stores source code of the vulnerable program.

This includes CVE-2022-22963, a Spring SpEL / Expression Resource Access Vulnerability, as well as CVE-2022-22965, the spring-webmvc/spring-webflux…

This is a filter bypass exploit that results in arbitrary file upload and remote code execution in class.upload.php <= 2.0.3

Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass…

Scans selected files for patterns stated in rules. This is used in order to find secrets you may have accidentally written to a file. This scanner is…

Affected versions of this package are vulnerable to Prototype Pollution.

This vulnerability arises from incomplete sandboxing in js2py, where crafted JavaScript can traverse Python’s internal object model and access…

This is a Python Application that helps you detect if your machine that run bash is vulnerable by CVE-2014-6271