
Node.js-CVE-2017-5941
Educational demo of Node.js insecure deserialization (CVE-2017-5941) with cookie-based payload injection and reverse shell exploitation for security…

Educational demo of Node.js insecure deserialization (CVE-2017-5941) with cookie-based payload injection and reverse shell exploitation for security…

A patched version of the V8 JavaScript engine addressing CVE-2021-0393, providing a secure baseline for Android 10 R33 builds.

CVE-2025-68613

Step-by-step exploitation guide for Apache ActiveMQ CVE-2015-5254 deserialization vulnerability using jmet, with Docker-based lab setup and…

Detailed disclosure of CVE-2024-34831: Stored XSS in GibbonEdu Core v26.0.00 leading to privilege escalation via crafted imageLink parameter and…

CVE-2024-42758 - Dokuwiki (indexmenu plugin) - XSS Vulnerability

Cross Site Request Forgery (CSRF) in Commercify v1.0

Proof-of-concept exploit for CVE-2023-46449: IDOR in Sourcecodester inventory management system v1.0 password change function enabling remote account…



Docker-based lab demonstrating CVE-2019-9193 PostgreSQL arbitrary command execution via COPY FROM PROGRAM, with step-by-step PoC for security testing…

CVE-2023-46450 reference

Educational analysis of Apache Struts 2 RCE vulnerability CVE-2017-5638, including exploit details, Equifax case study, and prevention measures.

Proof-of-concept exploit for CVE-2026-21858 (ni8mare) impacting n8n versions < 1.121.0

📱 🐟 An app to remote control SocialFish.

An Open-Source Pre and Post Callback-Based Framework for macOS Kernel Monitoring.

Curated repository of live malware samples and source code for educational malware analysis and research, with an organized database and CLI tools…