
CVE-2026-30951
Sequelize JSON Cast SQL Injection

Sequelize JSON Cast SQL Injection

CVE-2026-25632 — Fix Unsafe JSON Deserialization Leading to Remote Code Execution

We've set up an environment to test CVE-2025-57833. This environment was built using AI, so it's subject to ongoing modification.


Stack overflow in LibXMP

Python script using r2pipe to detect CVE-2017-13208 in Android libnetutils.so by checking for missing dhcp_size validation via static binary analysis.

Are you get Tanstack Supply chain attack attack of 5/11? CVE-2026-45321 / GHSA-g7cv-rxg3-hmpx

Analyzes a specific CVE in WeChat OAuth handler, identifying unbounded HTTP response reads leading to denial of service, with remediation guidance.

I have created AegisJava, a tool to fix (detect and mitigate) CVE-2025-30749.

Public disclosure for CVE-2023-31584.

Reproduction and root cause analysis of CVE-2024-35333, a stack buffer overflow in html2xhtml 1.3, with ASan crash output and code-level mitigation…

Behavior-preserving fix for CVE-2025-60876 HTTP header injection in BusyBox wget, with proof-of-concept, percent-encoding patch, and upstream…

Go proof-of-concept demonstrating CVE-2026-46595 in golang.org/x/crypto/ssh, using symbol inspection of stripped binaries and image scans to verify…

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…