
CVE-2026-34975
CRLF Email Header Injection in Plunk via raw MIME construction — CVSS 8.5

CRLF Email Header Injection in Plunk via raw MIME construction — CVSS 8.5

A curated list of useful resources that cover Offensive AI.

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level…

Cloud, CDN, and marketing services leveraged by cybercriminals and APT groups

Analysis of malware and Cyber Threat Intel of APT and cybercriminals groups

All the materials for Gareth Heyes' Black Hat talk: CSS: the bomb inside your inbox.

Artifacts for the USENIX publication.

Project Mantis: Hacking Back the AI-Hacker; Prompt Injection as a Defense Against LLM-driven Cyberattacks

Published security research repository featuring academic papers on domain hijacking, 2FA bypass, and large-scale spoofing techniques, authored by…

CVE-2026-13156 Vulnerability Advisory & PoC — Discovered by Huynh Kien Minh (MinhHK).

Writeup on CVE-2020-28328: SuiteCRM Log File Remote Code Execution plus some bonus Cross-Site Scripting


CVE-2024-3094 XZ Utils backdoor research - attack surface visualiser, system vulnerability checker, and general Linux CVE assessment tool

Public disclosure for CVE-2025-56526 and CVE-2025-56527 — Stored XSS via unsanitized PDF content rendering and plaintext credential exposure in…

Proof-of-concept demonstrating a Clickjacking vulnerability on the G1 website, with a malicious iframe overlay and social engineering popup for…

CVE-2026-30691: Stored Cross-Site Scripting (XSS) in @cyntler/react-doc-viewer

A public disclourse of CVE-2025-67730 in Frape lms By dharan ragunathan

Security advisory detailing a critical CVE in Copilot AI where RAG-based citation links are forged to a third-party domain, enabling source…