
GoCD_PoC_Supply_Chain_Attack
CVE-2021-43287 CVE-2021-43288 CVE-2021-43289 CVE-2021-43290

CVE-2021-43287 CVE-2021-43288 CVE-2021-43289 CVE-2021-43290

PoC for CVE-2026-7669: SGLang silent trust_remote_code override -> RCE

Proof-of-concept exploit for CVE-2026-44590, a command injection in Sherlock's GitHub Actions workflow enabling RCE and GITHUB_TOKEN exfiltration via…

PoC for CVE-2026-4660: arbitrary file read via git checkout in hashicorp/go-getter

Proof-of-concept demonstrating arbitrary code execution in Orval via malicious OpenAPI fields, with setup, exploit steps, and remediation guidance.

Exploit for CVE-2026-33017, an unauthenticated RCE in Langflow 1.8.1 via the build_public_tmp endpoint, enabling Python code injection through…

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

Reproduces a stack-exhaustion denial-of-service in deepmerge-ts before 8.0.0, documents exploitation, and includes a scanner for vulnerable…

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

PoC for CVE-2026-22018, a critical Jenkins Pipeline Shared Library RCE via Groovy @Grab, demonstrating supply-chain code injection and mitigation…

Personal repository of security advisory disclosures covering vulnerabilities in web, cloud, infrastructure, and open-source software.

Malicious Maven pom.xml that uses "groovy-maven-plugin" to get RCE

PHP 8.1.0-dev User-Agentt Backdoor Remote Code Execution (RCE)

Advisory for textract ⌯⌲ 15 000 weekly downloads

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

GameLoop update MITM

Detect CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Fast, accurate scanner with zero false positives.