
CVE-2026-8888-Printer-Firmware-Unsigned-Update-via-HTTP
Demonstrates CVE-2026-8888, an unsigned printer firmware update over HTTP, including a malicious update server and vulnerable printer emulator for…

Demonstrates CVE-2026-8888, an unsigned printer firmware update over HTTP, including a malicious update server and vulnerable printer emulator for…

PoC for CVE-2026-22018, a critical Jenkins Pipeline Shared Library RCE via Groovy @Grab, demonstrating supply-chain code injection and mitigation…

Demonstrates how a malicious Python package executes arbitrary commands during pip install via setup.py, highlighting PyPI supply chain and…

Demonstration exploit for CVE-2022-32223: DLL hijacking in Node.js on Windows via malicious providers.dll, targeting OpenSSL installations.

This repository contains a Bash script and a one-liner command to verify if a system is running a vulnerable version of the "xz" utility, as…

Technical analysis and proof-of-concept for CVE-2026-55200, a critical heap-based buffer overflow in libssh2 allowing pre-authentication RCE.…

A local package installation helper trusted caller-supplied package names too much. In yeoman-environment, missing generators could be installed…

Static web application for viewing SBOMs and performing on-demand vulnerability scanning with osv.dev. Easily deployable to GitHub/GitLab Pages.

POC of CVE-2021-42574 for solidity and solc compiler

Ansible playbooks designed to check and remediate CVE-2024-3094 (XZ Backdoor)

Curated resource hub for Log4j CVE-2021-44228, covering detection, mitigation, exploitation, and dependency management strategies for the critical…

Automated Snyk vulnerability scanning for dependencies and Docker images in Bitbucket Pipelines, with severity thresholds and monitoring options.

Technical writeup and Proof of Concept (PoC) for CVE-2026-11417: OS Command Injection / Remote Code Execution (RCE) in AWS CDK's NodejsFunction.

Scanner for the Mini Shai-Hulud npm/PyPI supply chain worm (NHS CC-4781 · CVE-2026-45321). Detects gh-token-monitor persistence, payload artefacts,…

Professional vulnerability assessment report for Helm plugin path traversal risk, including technical analysis, impact, remediation, and mitigation…

Proof-of-concept exploit for CVE-2024-55587 in libarchive, demonstrating unsafe extraction via malicious ZIP files.

Research environment and validation scripts for evaluating deserialization behaviors in MLflow and MLServer.

Bash PoC for CVE-2024-32002 that exploits Git clone with malicious submodules and symlinks to execute arbitrary commands on Windows and macOS.