
CVE-2026-51302-PoC
Clickbait. The CVE is AI slop.

Clickbait. The CVE is AI slop.

Bloomberg Memray’s Stored XSS via Unescaped Command-Line Metadata

Documentation of CVE-2023-31606: a ReDoS vulnerability in Redcloth gem's sanitize_html function, with root cause analysis, CVSS 7.5 scoring, and…

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…

A security-hardened fork of "Simply Show Hooks". Replaces the compromised original (CVE-2024-6297) and patches unlisted Cross-Site Scripting (XSS)…

Command-line static analysis scanner that detects critical vulnerabilities in PHP and YAML source code using custom semgrep rules, with Jira and…

CVE's I found. technical writeups, expolitation examples and fuzzing sessions walkthroughs

Synthetic CWE-120 stack buffer overflow variant of CVE-2020-8597 (pppd EAP) as a CodeQL static-analysis target

Cursor plugin for Hono v4 (TypeScript edge web framework). 59 LLM regressions with BAD/CORRECT pairs. Pinned to hono ^4.12.19 (>= 4.9.7 for…

Java utility library with patched CVE-2022-4244 vulnerability, providing common helper classes for I/O, reflection, and CLI argument parsing in…

PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container

Utilize Tai-e to identify the Log4shell (a.k.a. CVE-2021-44228) Vulnerability

Proof-of-concept exploit for terminal escape sequence injection via malicious filenames that hides Flawfinder's scan findings; fixed in version…

SyncShield - Browser Extension to Detect Unsafe Rsync Commands (CVE-2018-5764)

Proof-of-concept exploit and technical advisory for an Admin+ arbitrary file upload to remote code execution vulnerability in Everest Toolkit…

A CodeQL query to find CVE 2022-35737

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

Generates five .NET deserialization payload formats for CVE-2026-56158, delivers them over HTTP/SOAP/JSON endpoints, includes mock server, scanner,…