
CVE-2026-5059-poc
Proof-of-concept demonstrating command injection in aws-mcp-server via shell=True, with analysis of the vulnerable code and the fix in v1.7.0.

Proof-of-concept demonstrating command injection in aws-mcp-server via shell=True, with analysis of the vulnerable code and the fix in v1.7.0.

Educational lab demonstrating CVE-2026-2964, a prototype pollution vulnerability in web-audio-recorder-js leading to RCE. Includes vulnerable and…

Demonstrates a proof-of-concept for CVE-2026-35414, showing a vulnerable and fixed version of SSH principal matching logic to illustrate the flaw.

Example Vulnerable application for CVE-2025–57833

Educational lab demonstrating JavaScript expression sandbox escape techniques and patch evolution through multiple vulnerable sandbox versions, with…

The Python Version of our Not Go-ing Anywhere Vulnerable Application

Defensive vulnerability-research project comparing vulnerable and patched Grandstream GXP1600 firmware for CVE-2026-2329, using SquashFS extraction,…

Detects the CVE-2026-42945 rewrite pattern in nginx configs: rewrite with ? in the replacement plus an unnamed capture consumed in the same location

Synthetic CWE-120 stack buffer overflow variant of CVE-2020-8597 (pppd EAP) as a CodeQL static-analysis target

Detect and patch vulnerable Apache Commons Text in Java JAR/WAR artifacts; fingerprint classes and scan bytecode for CVE-2022-42889 (Text4Shell) call…

Scanning tool for identifying local privilege escalation issues in vulnerable MSI installers

Educational examples porting Linux kernel vulnerabilities to Rust, featuring intentionally vulnerable code and exploits for learning kernel security…

Educational proof-of-concept demonstrating SQL injection via dynamic aliases in Django's annotate() and alias() methods (CVE-2025-57833). Includes…

A vulnerable version of Rails that follows the OWASP Top 10

Go package that checks if RSA keys are vulnerable to ROCA / CVE-2017-15361

Detection script for cve-2021-23358

Educational lab demonstrating CVE-2020-7598 prototype pollution in minimist with a vulnerable Node.js/Express app, exploit payload, and…

Decompiled source code of zip4j library versions 1.3.2 (vulnerable) and 1.3.3 (fixed) for CVE-2018-1002202 path traversal analysis, part of the…