

PoC exploit for CVE-2026-73678: unauthenticated RCE in MindsDB Cowork via attacker-supplied LLM key and unsandboxed scratchpad exec to run OS…

Scanner: CVE-2025-34291 Langflow Origin Validation Error / CORS Misconfiguration — Python checker (CISA KEV)

Academic purposes only. Attack against Salesforce lightning with guest privilege.

Milvus 认证安全检测脚本:CVE-2025-64513 (sourceid后门) / CVE-2026-26190 (/expr弱token) / 内部端口53100

Validates Google Maps API keys against 21 endpoints, revealing exposed services with PoC URLs, proxy support, and quiet mode for focused auditing.

Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD…

Simple JMX RMI scanning tool

find sensitive data leaking from ServiceNow instances.

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

Drop-in fix for the unpatched MCP STDIO command-injection flaw (CVE-2026-30623 family)

Getting a handle on container security

DonkAI is a hands-on lab for the OWASP Top 10 for LLM Applications (2025) - no real LLM required.

OWASP ServerlessGoat: a serverless application demonstrating common serverless security flaws

The code for personally reproducing the corresponding vulnerability

演示 Next.js 中的 Middleware 授權繞過漏洞 (CVE-2025-29927) 允許未經授權的用戶存取受保護的資訊。

CVE-2021-3707 , CVE-2021-3708

Here's a Python script that checks if the polyfill.io domain is present in the Content Security Policy (CSP) header of a given web application.