
enforcement-coverage
Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

解决网络安全漏洞

Security hardening toolkit for COBOL legacy systems — invisible Unicode detection, format boundary analysis, source transformation integrity

Synthetic CWE-120 stack buffer overflow variant of CVE-2020-8597 (pppd EAP) as a CodeQL static-analysis target

Generates five .NET deserialization payload formats for CVE-2026-56158, delivers them over HTTP/SOAP/JSON endpoints, includes mock server, scanner,…

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Proof-of-concept exploit and technical advisory for an Admin+ arbitrary file upload to remote code execution vulnerability in Everest Toolkit…

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

Clickbait. The CVE is AI slop.

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

Bookea-tu-Mesa is vulnerable to SQL Injection

Java utility library with patched CVE-2022-4244 vulnerability, providing common helper classes for I/O, reflection, and CLI argument parsing in…

SyncShield - Browser Extension to Detect Unsafe Rsync Commands (CVE-2018-5764)

Fix prototype pollution vulnerability (CVE-2023-26136) for tough-cookie package

CVE-2026-39259

Documentation of CVE-2023-31606: a ReDoS vulnerability in Redcloth gem's sanitize_html function, with root cause analysis, CVSS 7.5 scoring, and…

PHP script to detect CVE-2015-6835 (session deserialization vulnerability) by analyzing source code for unsafe unserialize() calls in session…