
CVE-2525-25748-Cross-Site-Request-Forgery-CSRF-Vulnerability-in-HotelDruid-3.0.7
Detailed CVE-2025-25748 proof-of-concept and analysis of a CSRF vulnerability in HotelDruid 3.0.7, including exploitation flow, impact assessment,…

Detailed CVE-2025-25748 proof-of-concept and analysis of a CSRF vulnerability in HotelDruid 3.0.7, including exploitation flow, impact assessment,…

Proof-of-concept for a reflected XSS vulnerability in AIBOX's chat component, demonstrating JWT token theft and account hijacking via crafted…

Educational analysis of Apache Struts 2 RCE vulnerability CVE-2017-5638, including exploit details, Equifax case study, and prevention measures.

A Stored Cross-Site Scripting (XSS) vulnerability exists in Issabel-PBX version 4.0.0-6. The application fails to properly sanitize and encode…

Comprehensive open-source book on SELinux covering kernel components, userspace libraries, policy toolchain, and policy language. Includes build…

A tool for effective testing the binding layer of scripting languages

GNU IFUNC is the real culprit behind CVE-2024-3094

CodeQL + DTrace = Memory Disclosure Vulnerabilities in XNU

The Intelligent Process Lifecycle of Active Cyber Defenders

Technical analysis, root cause breakdown, and non-destructive detection methodology for CVE-2026-63030.

Walkthrough: ingress-nginx Configuration Injection via rewrite-target Annotation

Rule-based CLI tool that grades organizational defenses against MITRE ATT&CK and D3FEND frameworks, detects security gaps, and proposes mitigations.…

Academic research on N-Day Linux kernel vulnerabilities, analyzing CVE-2024-36886 in the TIPC networking subsystem, lifecycle, impact, and mitigation…

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

A curated list of resources for learning about application security

An NFC research toolkit application for Android

This project shows the kind of data a rogue iPhone application can collect.

Static analysis CLI tool that reduces Node.js application attack surface by constructing dependency graphs and removing unused modules and functions…