
CVE-2026-21015-PHP-Filter-Chain-Arbitrary-File-Read
PoC exploit for CVE-2026-21015 that abuses PHP filter chains to read arbitrary files through a vulnerable include() call, disclosing source and…

PoC exploit for CVE-2026-21015 that abuses PHP filter chains to read arbitrary files through a vulnerable include() call, disclosing source and…

Python exploit for CVE-2026-3333 demonstrating DNS rebinding to access cloud metadata and steal IAM credentials through an SSRF-vulnerable web app.

An at-rest encrypted filesharing application with multiple clients who seek to share privately, without tracking.

Easy peasy file uploads

A transparent PII redaction proxy for LLM API traffic. Sits between an application and an LLM provider (currently Anthropic), pseudonymizing…

Scanning pastebin with yara rules

This Proof of Concept (PoC) demonstrates an exploit for CVE-2024-42009, leveraging a cross-site scripting (XSS) vulnerability to extract emails from…

A privacy and security engineering toolkit: Discover, understand, pseudonymize, anonymize, encrypt and securely share sensitive and personal data:…

Objective: Demonstrate the exploitation of the Log4Shell vulnerability (CVE-2021-44228) within a simulated banking application environment.

Default Detections for EDR

An open source swiss army knife for arbitrary communication over application protocols

Cromos is a tool for downloading legitimate extensions of the Chrome Web Store and inject codes in the background of the application.

Extraction of iMessage Data via XSS

Password Manager Pro Exploit