
jupyter-notebooks
Example Jupyter notebooks that query VulnCheck APIs to chart exploitation timelines, Known Exploited Vulnerabilities, and botnet data for threat…

Example Jupyter notebooks that query VulnCheck APIs to chart exploitation timelines, Known Exploited Vulnerabilities, and botnet data for threat…

Technical analysis and detection guidance for CVE-2026-21589, a pre-auth path traversal arbitrary file access flaw in Atlassian Data Center products.

Harden chromium (somewhat) for privacy and security (and performance)

Python PoC exploiting Apache Tomcat CVE-2025-24813 partial PUT deserialization RCE, with auto variant detection, ysoserial gadget chains, and reverse…

Independent offline protocol-boundary regressions for published urllib3 fixes, with pinned releases and upstream attribution.

Vulnerable environment of CVE-2013-2251 (S2-016) for testing

Reference resources for Google's vulnerability reward programs, including domain tiers, OSS repository tier lists, and rewarded patch examples for…

Vulnerable environment of CVE-2020-17530 (S2-061) for testing

Proof-of-concept and research material for CVE-2026-59265, a LibreOffice and OpenOffice vulnerability, intended for authorized lab testing and…

Research materials and tooling for exploiting email address parser discrepancies to bypass access controls, including fuzzers, Hackvertor tags, CSS…

Simple PoC for demonstrating Race Conditions on Websockets

Sample Burp Suite extensions demonstrating the Montoya API, covering HTTP and proxy handlers, custom scan checks, Intruder payloads, WebSocket…

Disabled TLS Certificate Verification for HashiCorp Vault KMS in confluent-kafka

Proof-of-concept and research material for CVE-2026-4480, an OS command injection RCE in the Samba printing subsystem via the %J print command…

Community-contributed JSON dataset of XSS payload vectors powering the PortSwigger XSS cheat sheet, with browser support and interaction metadata.

ASLR-independent nginx RCE chain PoC combining the PoolSlip heap over-read leak (CVE-2026-9256) with the rift overflow (CVE-2026-42945) to reach…

Deliberately vulnerable Android app for mobile security research and bug bounty practice - OWASP Mobile Top 10

Proof-of-concept and Docker lab reproducing CVE-2026-0603, a second-order SQL injection in Hibernate ORM bulk DELETE/UPDATE operations, with…