
log4j-vuln-coverage-check
A simple project to check coverage of Log4J vuln CVE-2021-44228 (and related)

A simple project to check coverage of Log4J vuln CVE-2021-44228 (and related)

Exploit for CVE-2022-25175 targeting Jenkins Pipeline: Multibranch plugin, enabling automated exploitation of a specific vulnerability in CI/CD…

Proof-of-concept exploit for CVE-2023-1521 demonstrating LD_PRELOAD-based privilege escalation in sccache, enabling arbitrary code execution during…

Demonstrates exploitation of CVE-2017-8046 in a Spring Boot application, including a SpEL injection payload and dependency-check verification for…

PoC demonstrating SHA-1 code signing forgery and missing High Entropy ASLR in CyberGhostVPN installer, enabling trust bypass and predictable memory…

Debian Lenny Bash packages with cve-2014-6271 patches (i386 and amd64)

CVE-2023-37478 showcases how a difference in npm and pnpm install packages that could be exploited by a well crafted tar.gz packge. This repo shows a…

Patched version of Expat XML parser for AOSP10, addressing CVE-2022-25236. Provides source code for vulnerability analysis and educational review of…

It was determined that malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. # It was determined that only…

Proof-of-concept and analysis tools for CVE-2024-3094, the XZ Utils backdoor vulnerability, including detection and exploitation scripts.

Minimal CVE-2024-3094 reference repository documenting the xz backdoor vulnerability, affected versions (5.6.0/5.6.1), and mitigation steps. Includes…

Patched version of the uploader.swf and uploaderSingle.swf to fix CVE-2011-2461

Log4Shell (CVE-2021-44228) security remediation demo - Showcasing Antigravity's ability to identify and fix critical security vulnerabilities in Java…

vulnerabilities, CVE-2022-41903, and CVE-2022-23521, that affect versions 2.39 and older. Git for Windows was also patched to address an additional,…

Analyzes and demonstrates the webpack CVE-2024-43788 vulnerability, providing detection and exploitation insights for security researchers.

Created after the disclosure of CVE-2021-44228. Bash script that detects Log4j occurrences in your projects and systems, allowing you to get insight…

Scan local repos for vulnerable axios versions (CVE-2026-40175) and patch interactively

Exploit for CVE-2026-33017, an unauthenticated RCE in Langflow 1.8.1 via the build_public_tmp endpoint, enabling Python code injection through…