
HosTaGe
Low Interaction Mobile Honeypot

Low Interaction Mobile Honeypot

Educational proof-of-concept replicating CVE-2021-38297, a Go WASM buffer overflow leading to stored XSS. Includes vulnerable app setup, exploit…

Research tool that scans SSH services for authentication bypasses, timing leaks, weak keys, and post-session exposures, with JSON output and analysis.

Serverless Functions for establishing Reverse Shells to Lambda, Azure Functions, and Google Cloud Functions

CVE-2026-42978 Windows Push Notifications (WpnService) Use-After-Free & Race Condition PoC research, diagnostic scanner, and security audit module…

PoC — symlink following to out-of-repo content disclosure via search_text in Gortex (GHSA-6vhf-4wcm-2r83, CVE-2026-87003, CVSS 5.5).

Defense framework that keeps audio-language models frozen and adds a mid-layer risk gate with late-layer safety adapters to block audio jailbreaks at…

Stored Cross-Site Scripting (XSS) in Xibo Signage's Xibo CMS v4.1.2, due to a lack of proper validation of user input.

An issue was discoverd in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive…

Awesome information for WebSockets security research

Public version of the Entropica repo

SCAN END POC THE CVE-2024-4367

The Online Diagnostic Lab Management System has a security problem called Cross-Site Scripting (XSS) in the Borrower section.

CVE-2025-54123 exploit and documentation

Artefacts for blog post on finding CVE-2025-37899 with o3

Microsoft Edge Elevation of Privilege Vulnerability

A Linux Host-based Intrusion Detection System based on eBPF.

Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known…