
CVE-2026-26720-Twenty-RCE
Proof-of-concept for authenticated remote code execution in Twenty CRM via unsandboxed serverless workflow functions, allowing arbitrary Node.js…

Proof-of-concept for authenticated remote code execution in Twenty CRM via unsandboxed serverless workflow functions, allowing arbitrary Node.js…

A static + runtime security scanner for MCP (Model Context Protocol) servers

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.

Octoscan is a static vulnerability scanner for GitHub action workflows.

ngxray — nginx config security scanner


Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

CVE-2026-42533 Nginx

CVE-2026-60137Temporary Emergency Mitigation for CVE-2026-60137 & CVE-2026-63030 (wp2shell)

Exploit for CVE-2021-44667 targeting Alibaba Nacos 2.0.3, enabling unauthenticated remote code execution via a crafted request to the Derby database…

Proof-of-Concept (POC) of a simple firewall in Python designed to mitigate the Spring4Shell (CVE-2022-22965) RCE attack by inspecting and blocking…

Fastest filesystem scanner for log4shell (CVE-2021-44228, CVE-2021-45046) and other vulnerable (CVE-2017-5645, CVE-2019-17571, CVE-2022-23305,…

Fixes CVE-2021-44228 in log4j by patching JndiLookup class

Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass…

Ruby script to fix quote attribution vulnerability (CVE-2023-45806) in Discourse forums by searching and patching malformed quote blocks with…

Detect and fix log4j log4shell vulnerability (CVE-2021-44228)