



Proof-of-concept exploit and technical advisory for an Admin+ arbitrary file upload to remote code execution vulnerability in Everest Toolkit…

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata

Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

This skill helps Claude write secure code and prevent common vulnerabilities.

OSWE, OSEP, OSED, OSEE

CVE's I found. technical writeups, expolitation examples and fuzzing sessions walkthroughs

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

Bookea-tu-Mesa is vulnerable to SQL Injection

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container
