
cve-2021-33879
GameLoop update MITM

GameLoop update MITM
Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

Demonstrates exploitation of CVE-2017-8046 in a Spring Boot application, including a SpEL injection payload and dependency-check verification for…

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

Exploit for remote command execution in Golang go get command.

Security training for the apps you actually ship. Open your browser and start hacking.

Proof-of-concept for CVE-2021-26700: remote code execution in the VSCode npm-script extension via malicious workspace settings.json, with detailed…

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

Repository for CVE-2014-4936 POC code.

PHP 8.1.0-dev User-Agentt Backdoor Remote Code Execution (RCE)

CocoaPods RCE Vulnerability CVE-2024-38366

PoC for CVE-2026-4660: arbitrary file read via git checkout in hashicorp/go-getter

Detailed disclosure of CVE-2025-68664, a critical deserialization vulnerability in LangChain core allowing secret exfiltration and potential RCE via…

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

GNU IFUNC is the real culprit behind CVE-2024-3094

A security-hardened fork of "Simply Show Hooks". Replaces the compromised original (CVE-2024-6297) and patches unlisted Cross-Site Scripting (XSS)…

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

PoC for CVE-2026-7669: SGLang silent trust_remote_code override -> RCE