
CVE-2026-23947-PoC
Proof-of-concept demonstrating arbitrary code execution in Orval via malicious OpenAPI fields, with setup, exploit steps, and remediation guidance.

Proof-of-concept demonstrating arbitrary code execution in Orval via malicious OpenAPI fields, with setup, exploit steps, and remediation guidance.

Protects software supply chain integrity by verifying each step is performed by authorized functionaries, using signed layout and link metadata.

Docker Model Runner container-to-host RCE / Escape: A critical vulnerability that allows for container-to-host code execution in the Docker Model…

Collection's of Tech Talk that are presented by me :)

Demonstrates how a malicious Python package executes arbitrary commands during pip install via setup.py, highlighting PyPI supply chain and…

Scans project dependencies for dependency confusion vulnerabilities and checks package owner email takeover risks across multiple registries (npm,…

Malicious Maven pom.xml that uses "groovy-maven-plugin" to get RCE

nltk.tokenize.StanfordSegmenter dynamically loads external Java .jar files without verification or sandboxing. If an attacker can supply or replace…

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

Apache RAT (Release Audit Tool) Gradle Plugin

Software Component Verification Standard (SCVS)

Patched version of the uploader.swf and uploaderSingle.swf to fix CVE-2011-2461

DO NOT FORK, DEPLOY, OR USE FOR ANYTHING BUT LEARNING. These requirements are vulnerable to CVE-2024-39689

CVE-2024-24787 Proof of Concept

CVE-2025-53547 one of poc code

Scan code for invisible bidirectional Unicode characters (Trojan Source attack prevention, CVE-2021-42574)

Agent-powered vulnerability scanner for large-scale codebases. Uses LLMs to find hard-to-detect security issues via regex matchers and AI…

Proof of concept of CVE-2017-1000117