
CVE-2026-32722
Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata

Clickbait. The CVE is AI slop.

A CodeQL query to find CVE 2022-35737

Proof-of-concept exploit and technical advisory for an Admin+ arbitrary file upload to remote code execution vulnerability in Everest Toolkit…

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

Generates five .NET deserialization payload formats for CVE-2026-56158, delivers them over HTTP/SOAP/JSON endpoints, includes mock server, scanner,…

A security-hardened fork of "Simply Show Hooks". Replaces the compromised original (CVE-2024-6297) and patches unlisted Cross-Site Scripting (XSS)…

解决网络安全漏洞

CVE's I found. technical writeups, expolitation examples and fuzzing sessions walkthroughs

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

Command-line static analysis scanner that detects critical vulnerabilities in PHP and YAML source code using custom semgrep rules, with Jira and…

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…

Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability

Security hardening toolkit for COBOL legacy systems — invisible Unicode detection, format boundary analysis, source transformation integrity

Synthetic CWE-120 stack buffer overflow variant of CVE-2020-8597 (pppd EAP) as a CodeQL static-analysis target

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

CVE-2026-39259