
jetty-9.4.31.v20200723_CVE-2023-26049
Exploit code and analysis for CVE-2023-26049 targeting Jetty 9.4.31, demonstrating a vulnerability in the web server for security testing and…

Exploit code and analysis for CVE-2023-26049 targeting Jetty 9.4.31, demonstrating a vulnerability in the web server for security testing and…

Find authentication (authn) and authorization (authz) security bugs in web application routes.

A locally hosted page for cheat sheets. Currently being used for reverse engineering and hosted in labs so I can limit or forgo (lock down firewall)…

Defensive analysis of CVE-2009-4496 in Boa 0.94.14rc21, including source-code review, patch analysis, severity assessment, and ethical scope.

Educational demo of three Claude Code vulnerabilities (hooks bypass, MCP injection, API key exfiltration) with attacker server, MITM proxy, and…

Security scanner to detect CVE-2025-55182 & CVE-2025-66478 vulnerabilities in React Server Components (RSC) projects

🔍 Scan for CVE-2025-55182 risks in React Server Components with this non-intrusive tool that helps detect critical vulnerabilities in your…

MCP Server for Ghidra

Plugin for JADX to integrate MCP server

a fast check, if your server could be vulnerable to CVE-2021-44228

Model Context Protocol server for autonomous vulnerability discovery

C++ library for detecting cross-site scripting (XSS) vulnerabilities in URLs through pattern analysis, with server modules and command-line tools for…

Standalone MCP server plugin for IDA Pro.

Detects whether a website uses React Server Components (RSC) or Next.js, aiding in vulnerability assessment for CVEs like CVE-2025-55182.

🛡️ Audit your Next.js & React Server Components stack for critical vulnerabilities (CVE-2025-66478, CVE-2025-55184). Detects risks & generates fix…

Benchmark task for reimplementing a masked path-resolution fix in Jupyter Server, with functional and hidden security tests to evaluate…

Critical heap buffer overflow vulnerability in the handle_trace_request and parse_trace_request functions of the Fluent Bit HTTP server.

CodeQL-based analysis of CVE-2025-55182 prototype pollution vulnerability in React Server Components, with exploit POC and static detection queries…