
firmware-reverse-engineering
Agent skills for firmware extraction, static analysis, Ghidra reverse engineering, emulation, and security reporting, packaged for Claude Code and…

Agent skills for firmware extraction, static analysis, Ghidra reverse engineering, emulation, and security reporting, packaged for Claude Code and…

Educational repository for CVE-2026-10795 research, providing proof-of-concept resources and guidance for authorized security testing in isolated…

Educational repository for researching CVE-2026-83548 and CVE-2026-83549, providing proof-of-concept resources and guidance for authorized security…

Docker lab for validating the CVE-2026-75650 Magento component-level PHP execution primitive and Adobe VULN-39341 patch.

Provides a proof-of-concept check script and documentation for CVE-2024-31969, a local privilege escalation in sudo's sudoedit, including affected…

Sell bookable services and appointments through WooCommerce -- closes CVE-2026-2931 by construction.

Educational proof-of-concept for Telerik padding oracle vulnerabilities (CVE-2026-13181-184) with scripts for authorized security testing and…

Technical analysis of the XZ Utils backdoor (CVE-2024-3094), explaining the supply chain attack, obfuscation techniques, and impact on OpenSSH via…

Free security-baseline rule for Claude Code, Codex, and Cursor: treats MCP tool descriptions as untrusted input (OWASP MCP Top 10 MCP03,…

Educational proof-of-concept for CVE-2026-67276, targeting MikroTik RouterOS vulnerabilities. Includes setup scripts and references for authorized…

Security-research lab reproducing CVE-2026-45132 (pwn request via pull_request_target chart-name injection in generate-schema.yaml) — snapshot of…

Defensive security research repository detailing CVE-2026-58138, an unauthenticated RCE in Conductor via GraalVM. Provides technical analysis,…

Reproduces CVE-2026-39866, a workflow_dispatch input template injection in a GitHub Actions workflow, using a pinned snapshot of the vulnerable…

Community-owned database of security advisories for Python packages on PyPI, providing structured vulnerability data in OSV format for integration…

Non-destructive PostgreSQL vulnerability checker for CVE-2026-6471. Audits server version and REPLICATION privileges to identify exposure to logical…

Structured threat intelligence dataset for tracking CVE vulnerabilities with CVSS scores, KEV status, and publication dates.

Documentation repository for Kismet, a wireless network detector, sniffer, and intrusion detection system. Includes guides, configuration references,…

Curated collection of CVE advisories and vulnerability information for security research and reference.