
CVE-2025-9267
Seagate Toolkit for Windows (Installer <2.35.0.6) is vulnerable to insecure DLL loading. The installer loads DLLs from the working directory without…

Seagate Toolkit for Windows (Installer <2.35.0.6) is vulnerable to insecure DLL loading. The installer loads DLLs from the working directory without…

A Python library to parse, validate and create SPDX documents.

CocoaPods RCE Vulnerability CVE-2024-38366

Educational demonstration of CVE-2007-4559 Python tarfile symlink attack with a script showing why os.path.realpath() fails to prevent extraction…

CVE-2024-38526 - Polyfill Scanner

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

Advisory and proof-of-concept for OS command injection in an MCP ffmpeg helper, with root-cause analysis, detector guidance, and mitigations for an…

Detect CVE-2026-45321 Mini Shai-Hulud supply chain compromise — scans for 170 npm + 2 PyPI poisoned packages across TanStack, Mistral AI, UiPath,…

Demonstration of CVE-2017-1000117: a Git vulnerability triggered by recursive cloning of malicious submodules, causing arbitrary command execution.

Detailed analysis of a critical pre-authentication out-of-bounds write vulnerability in libssh2 leading to remote code execution, with root cause,…

Bash script to detect and remediate CVE-2024-3094, a critical supply-chain vulnerability in the XZ Utils library, with automatic safe version…

Proof of concept of CVE-2017-1000117

golang.org/x/text v0.33.0 backport of CVE-2026-56852 (GO-2026-5970) for Go 1.24

Fork of lodash.template with CVE-2021-23337 fix (command injection via variable option)

Curated dataset of cloud middleware agents installed by AWS, Azure, and GCP, documenting past vulnerabilities, privileges, and attack-surface risks…

Quick and dirty PoC for checking whether a vulnerable version of xz-utils is installed (CVE-2024-3094)

This is an incident response playbook we created for the Vercel April 2026 compromise

Educational demo of three Claude Code vulnerabilities (hooks bypass, MCP injection, API key exfiltration) with attacker server, MITM proxy, and…