
CVE-2021-21239
A script to exploit a vulnerability in xmlsec1 where xmlsec ignores loaded public keys

A script to exploit a vulnerability in xmlsec1 where xmlsec ignores loaded public keys
Read-only Bash checker for the Copy Fail Linux kernel vulnerability (CVE-2026-31431)

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

Educational laboratory for studying CVE-2014-0160 (Heartbleed) and framing inconsistencies in TLS heartbeat handling.

Self-contained Heartbleed (CVE-2014-0160) lab: builds vulnerable OpenSSL 1.0.1f in Docker and includes a Python memory-leak PoC for authorised…

Cryptographically signed, replay-verifiable evidence layer for AI agents. Governs actions in the loop, produces Ed25519-signed receipts linked into a…

Some setup scripts for security research tools.

This project intends to provide a series of tools to craft, parse, send, analyze and crack a set of LoRaWAN packets in order to audit or pentest the…

Artifacts for the USENIX publication.

Proof-of-concept code for beating Google's ZK proof of quantum cryptanalysis

Testing TLS/SSL encryption anywhere on any port

🚀🚀 This is a 🎇🔥 REAL WORLD🔥 🎇 Malware Collection I have Compiled & analysed by researchers🔥 to understand more about Malware threats😈,…

Technical analysis and PoC of CVE-2026-52824: default APP_SECRET in the Kimai Docker image enabling unauthenticated login link forgery. Affects <=…

Python PoC and Docker lab for CVE-2026-61500: recovers Rejetto HFS V8 PRNG state to forge an admin session cookie and achieve RCE via server_code.

Implementation of the Google Zero-Knowledge library for Identity Protocols.

Test code for poodle attack (CVE-2014-3566)