
bigint-buffer-safe
Safe, pure-JS drop-in replacement for bigint-buffer. Fixes CVE-2025-3194 (CVSS 7.5). Zero dependencies, no native bindings.

Safe, pure-JS drop-in replacement for bigint-buffer. Fixes CVE-2025-3194 (CVSS 7.5). Zero dependencies, no native bindings.

CVE-2018-11235(PoC && Exp)

Critical supply-chain vulnerability research on NiceHash QuickMiner update mechanism (CVE-2025-56513). Includes technical analysis, attack scenarios,…

Test

Educational Python target range simulating CVE-2026-22807, an AI supply chain RCE via TOCTOU in model loading. Includes vulnerable library, PoC…

Synthetic demo target for Endor Labs EXPOSURE, tracking CVE-2024-12886 with a deliberately vulnerable dependency and a one-click PR-based fix…

Synthetic demo target for CVE-2024-10821 vulnerability detection and automated fix via compensating control. Demonstrates one-click PR-based…

repo for CVE-2025-55349

npm repo with ejs CVE-2022-29078 (CVSS 9.8, EPSS 32%) for Dependabot automerge testing

gradle cve

Sentinel demo: transitive snakeyaml CVE-2022-1471 via Spring Boot + exploitable code pattern

C library for parsing XML, patched for CVE-2022-23852, providing stream-oriented XML parsing with handlers for efficient document processing.

jee web project with log4shell (CVE-2021-44228) vulnerability

CVE-2023-37478 showcases how a difference in npm and pnpm install packages that could be exploited by a well crafted tar.gz packge. This repo shows a…

Presentazione per il corsi di sicurezza Informatica sulla vulnerabilità CVE-2024-3094

jee web project with sanitised log4shell (CVE-2021-44228) vulnerability

Checkov PoC: arbitrary code execution through auto-loaded configuration and unsigned external Python checks.