
semgrep-rules
A collection of my Semgrep rules to facilitate vulnerability research.

A collection of my Semgrep rules to facilitate vulnerability research.

Post-incident report on CVE-2026-20131 (CVSS 10.0), a Cisco FMC insecure deserialization vulnerability exploited by Interlock ransomware. Details…

Russian-language overview and analysis of the n-day vulnerability CVE-2026-27654, covering exploitation details and technical breakdown.

Open standard for documenting security-relevant metadata of AI models, including training data provenance, PII risk, known vulnerabilities, and…

Comprehensive database of x86/x64 instruction tables, latencies, and microarchitecture details for CPU performance analysis and low-level reverse…

Proof-of-concept and reference repository for CVE-2026-47761, a stored cross-site scripting (XSS) vulnerability in TinyMCE. Includes CVE details,…

This repository will contain many mindmaps for cyber security technologies, methodologies, courses, and certifications in a tree structure to give…

Public advisory landing page documenting CVE-2026-54520, a high-severity path traversal vulnerability in ai-agent-automation's workflow executor,…


Technical documentation and resources for CVE-2026-21250, a Windows HTTP.sys local privilege escalation vulnerability, including affected versions,…

Provides technical details and mitigation guidance for the Pack2TheRoot privilege escalation vulnerability (CVE-2026-41651) affecting Linux systems.

CVE-2026-1434 - Omega-PSIR is vulnerable to Reflected XSS via the lang parameter. An attacker can craft a...

CVE-2026-22849 - Saleor lacks proper HTML sanitization in rich text fields

Curated repository of vulnerability research write-ups with assigned CVEs, detailing discovered weaknesses, impact, and remediation across various…

Public disclosure and proof-of-concept for CVE-2025-61455, a critical SQL injection in E-commerce Project v1.0, including technical details, PoC, and…

A video presentation analysing the technical details, scale and lessons to be learned from the MOVEit CVE-2023=3462(CS50 Introduction to Cyber…

Proof-of-concept disclosure for CVE-2023-47437: stored cross-site scripting vulnerability in Pachno affecting comment forms. Includes affected…