
CVE-2025-47256
Stack overflow in LibXMP

Stack overflow in LibXMP

ReDoS explorando backtracking em regex, resultando em consumo excessivo de CPU e negação de serviço (DoS) em aplicações Node.js.

CVE-2019-10172 PoC and Possible mitigations

Detection script for cve-2021-23358

Educational CVE-2024-12877 exploit demo for PHP Object Injection in GiveWP WordPress plugin. Includes root cause analysis, regex bypass techniques,…

Arguments to reject CVE-2025-56005

Researching on the vulnrability CVE-2023-26136

Technical deep dive into Apache Log4j2 JNDI injection vulnerability. Features static code analysis, patch comparison, attack vectors (LDAP/RMI/DNS),…

Exploit for CVE-2020-35460 targeting MPXJ project management library, enabling arbitrary code execution via crafted project files in Java, .Net, and…

Java library for fast, configurable HTML sanitization from untrusted sources. Uses policy-driven scanning to remove malicious JavaScript and CSS,…

Exploit for CVE-2022-25173 targeting Jenkins Pipeline Groovy Plugin's CPS interpreter sandbox bypass, enabling arbitrary code execution within…

SkypeACLKeyGen.exe analysis for hacking team

Exploit for CVE-2011-4367 targeting Apache MyFaces JSF implementation, demonstrating a remote code execution vulnerability in the Jakarta Faces…

This repository contains a solution for the CVE-2023-26136 vulnerability.

AI Code Security — four agents that catch what SAST misses in AI-generated code. Built on GitLab Duo Agent Platform.

Proof-of-concept exploit for CVE-2022-0219, an XXE vulnerability in Jadx that allows local file disclosure when exporting malicious APK files via the…

Proof-of-concept exploit for CVE-2024-22640, a ReDoS vulnerability in TCPDF <=6.7.4 triggered by crafted HTML color input, with demonstration code.

Patched tough-cookie v2.5.0 fixing CVE-2023-26136 prototype pollution vulnerability with Object.create(null) in MemoryCookieStore, including exploit…