
-Ruby-dl-handle.c-CVE-2009-5147-
Community-maintained database of Ruby gem security advisories with structured CVE data, CVSS scores, and patched version requirements. Integrates…

Community-maintained database of Ruby gem security advisories with structured CVE data, CVSS scores, and patched version requirements. Integrates…

Python demo simulating CVE-2024-3094: a supply chain backdoor in XZ Utils with a trigger-based stealth activation.

Script to handle CVE 2022-42889

Demonstration of CVE-2021-44228 with a possible strategic fix.

CVE-2025-55182 Fix for Vibe Coders

Documented security vulnerabilities in the FatFs embedded filesystem library with CVE details, fuzzing harness, exploit disk-image generator, and…

Docker base image with backported Host header validation fix for CVE-2025-12543 in Undertow 1.4.x, enabling secure deployment of WildFly 11…

Issue with AWS SAM CLI (CVE-2025-3047, CVE-2025-3048)

CLI tool that verifies Docker images for CVE-2018-8115 by checking layers for malicious files, helping ensure safe pulls from Docker Hub.

It was determined that malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. # It was determined that only…

Proof of concept for CVE-2024-24590

Decompiled source code of zip4j library versions 1.3.2 (vulnerable) and 1.3.3 (fixed) for CVE-2018-1002202 path traversal analysis, part of the…

Educational demonstration of CVE-2007-4559 Python tarfile symlink attack with a script showing why os.path.realpath() fails to prevent extraction…

Hashes for vulnerable LOG4J versions

Curated collection of cybersecurity research reports covering CVE analysis, exploit research, threat intelligence, and offensive security from…

Breaking git with a carriage return and cloning RCE

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…

This repository provides a comprehensive security remediation of denial-of-service and allocation of resources without limits or throttling security…