
CVE-2026-50787
Security advisory detailing CVE-2026-50787, an uncontrolled resource consumption vulnerability in e-SIC Livre CAPTCHA generation, enabling remote…

Security advisory detailing CVE-2026-50787, an uncontrolled resource consumption vulnerability in e-SIC Livre CAPTCHA generation, enabling remote…

Security-oriented Go toolchain, focused on state-of-the-art fuzzing capabilities.

A visual no-code/code-free web crawler/spider易采集:一个可视化浏览器自动化测试/数据采集/网页爬虫软件,可以无代码图形化的设计和执行爬虫任务。别名:ServiceWrapper面向Web应用的智能化服务封装系统。

Unauthenticated OS command injection exploit for GPT-SoVITS Gradio web UI. Delivers RCE via unsanitized path parameters in audio-processing helpers,…

Automated XSS scanner and proof-of-concept exploit for CVE-2026-50229 in Apache Tomcat examples. Detects and exploits reflected cross-site scripting…

P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and…

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

CEREBRO-RED v2: Advanced LLM Red Team Research Platform with PAIR Algorithm and LLM-as-a-Judge Evaluation

A Reflected Cross-Site Scripting (XSS) vulnerability exists in Microworld Technologies eScan Management Console v14.0.1400.2281. The vulnerable…

Detailed CVE-2024-55187 advisory with proof-of-concept for a remote code execution vulnerability in phpIpam, exploiting path poisoning and PHAR file…

Proof-of-concept demonstrating log injection and poisoning in Splunk via crafted URL parameters, highlighting OWASP log injection risks.

A critical security vulnerability, identified as CVE-2023-50164 (CVE: 9.8) was found in Apache Struts, allowing attackers to manipulate file upload…

ERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method/frappe.desk.reportview.get endpoint via the…

Proof-of-concept for CVE-2023-50164 (Apache Struts 2), originally by jakabakos and adapted for the HTB Strutted lab environment. For educational use…

Proof-of-concept exploit for CVE-2016-10033, a remote code execution vulnerability in PHPMailer, demonstrating injection of additional sendmail…

CVE-2025-53652: Jenkins Git Parameter Analysis

PoC and Setup for CVE-2025-4664

Proof-of-concept demonstrating incorrect access control in Unifiedtransform v2.0, allowing teachers to view attendance for any class section via…