
Johnny-You-Are-Fired
Artifacts for the USENIX publication.

Artifacts for the USENIX publication.

Privacy-first behavioral intelligence framework for multi-platform analysis and sociodynamic research.

This repository contains the complete record of my three-year research journey, covering the project from foundational concepts to advanced-level…

Public PoC + Scanner and research for CVE-2025-68613: Critical RCE in n8n Workflow Automation via Expression Injection (CVSS 10.0). Includes…

CVE-2026-13156 Vulnerability Advisory & PoC — Discovered by Huynh Kien Minh (MinhHK).

PoC - Prueba de Concepto de CVE-2024-4367 en conjunto al CVE-2023-38831 en un solo Script

This repository contains validated detection rules for adversary behaviors observed during APT29 simulation. Each rule was tested against the actual…

Fish Live In Trees

Documentation and proof-of-concept for CVE-2026-30502, a reflected XSS vulnerability in OpenKM v6.3.12. Includes technical analysis, root cause,…

Stored Cross-Site Scripting (XSS) in Xibo Signage's Xibo CMS v4.1.2, due to a lack of proper validation of user input.

Detailed CVE-2026-51788 advisory for a DoS vulnerability in cleverange_auth v0.1.10, with technical analysis, CVSS scoring, and mitigation guidance…

CVE-2024-3094 XZ Utils backdoor research - attack surface visualiser, system vulnerability checker, and general Linux CVE assessment tool

🧨 CVE-2025-14783: Easy Digital Downloads Account Takeover PoC

This repository documents CVE-2026-48849, a Stored Cross-Site Scripting (XSS), HTML Injection, and CSS Injection vulnerability discovered in…

Coordinated disclosure of CVE-2025-52204: reflected XSS and HTML injection in Znuny OTRS customer.pl endpoint. Includes technical summary, affected…

Curated list of CVE-2020-0601 resources

CRLF Email Header Injection in Plunk via raw MIME construction — CVSS 8.5

A Stored Cross-Site Scripting (XSS) vulnerability exists in Issabel-PBX version 4.0.0-6. The application fails to properly sanitize and encode…