
Vulns
Collection of public proof-of-concept exploits for multiple CVEs, providing vulnerability demonstration code and references for security research and…

Collection of public proof-of-concept exploits for multiple CVEs, providing vulnerability demonstration code and references for security research and…

Harden chromium (somewhat) for privacy and security (and performance)

Reference resources for Google's vulnerability reward programs, including domain tiers, OSS repository tier lists, and rewarded patch examples for…

VEDAS-Driven Autonomous Generation + Community Contributions of Suricata & Nuclei Rules for over 12000 CVEs

Community-contributed JSON dataset of XSS payload vectors powering the PortSwigger XSS cheat sheet, with browser support and interaction metadata.

Lab reproducing CVE-2025-67727 (parse-community/parse-server ci-performance.yml pull_request_target RCE at e78e58d) — authorized security research

Developer-focused knowledge base of application security vulnerabilities with insecure vs secure code examples, prevention guidance, and OWASP/CWE…

Public security advisories and PoCs for vulnerabilities discovered in open-source web software, with root-cause analysis, CVE references,…

A collection of CVE exploits, including Python PoCs and README files with instructions for reproducing and exploiting each vulnerability.

Longitudinal anycast census system that probes IPv4/IPv6 prefixes via ICMP, TCP, and DNS to detect anycast deployments and geolocate PoPs, publishing…

Security portfolio of original responsible-disclosure findings, CTF and lab write-ups, methodology notes, and purpose-built pentest tooling covering…

Public write-up and disclosure timeline for CVE-2026-1769 (Stored XSS in Xerox CentreWare Web)

An ArchLinux based distribution for penetration testers and security researchers.

A beginner Obsidian Vault structure for Cybersecurity, Linux, Homelabbing / Self-hosting, all about sharing knowledge.

Stored XSS in Concrete CMS Community Store leads to admin dashboard takeover

Technical advisory and research notes for CVE-2026-16265, a Subscriber+ denial-of-service flaw in the WP Maps WordPress plugin fixed in version 4.9.7.

Security advisory and technical research notes for CVE-2026-18464, an unauthenticated denial-of-service flaw in the WP Maps Pro WordPress plugin…

Curated SIEM queries and techniques for offensive discovery of Windows privilege escalation, misconfigured ACLs, services, scheduled tasks, and…