
CVE-2026-10036-speechbrain-rce
SpeechBrain < 1.1.1 checkpoint metadata RCE via unsafe PyYAML parsing of CKPT.yaml.

SpeechBrain < 1.1.1 checkpoint metadata RCE via unsafe PyYAML parsing of CKPT.yaml.

Agentic Framework for Synthesizing CodeQL Queries

Deep dive into a critical SQL injection in Python's Ormar ORM — reproduction, fix, and tests

Educational presentation analyzing CVE-2021-21193, a use-after-free vulnerability in Google Chrome's Blink engine, including exploitation details and…

All stages of exploring the polkit CVE-2021-4034 using codeql

Technical write-up and PoC for CVE-2026-24009, demonstrating unsafe YAML loading in docling-core and practical mitigation paths.

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

Stored XSS via User-Agent in Admin Order View in PhocaCart

An Evaluation Agent for Detecting Misinformation and Knowledge Poisoning in Retrieval-Augmented Generation Systems.

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

Set of tools to assess and improve LLM security.

List of mixed boolean-arithmetic resources

Curated collection of LLVM security resources covering binary lifting, code obfuscation, static analysis, symbolic execution, sanitizers, and…

Structured vulnerability research repo for a Chrome Dawn WebGPU CWE-20 flaw: root cause, patch diff, static verification, severity review, and…

Non-weaponized CVE-2016-5195 (Dirty COW) analysis and validation harness with root-cause research, upstream patch review, and safe lab-only PoC for…

A list of Blockchain Security audit companies, solo auditors and location of public audits.

Select Bugs From Binary Where Pattern Like CVE-1337-Days

Demystifying Exploitable Bugs in Smart Contracts