
CVE-2026-55200
Detailed analysis of a critical pre-authentication out-of-bounds write vulnerability in libssh2 leading to remote code execution, with root cause,…

Detailed analysis of a critical pre-authentication out-of-bounds write vulnerability in libssh2 leading to remote code execution, with root cause,…

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

PHP 8.1.0-dev User-Agentt Backdoor Remote Code Execution (RCE)

Exploit for remote command execution in Golang go get command.


Detect CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Fast, accurate scanner with zero false positives.

Sonatype Nexus 2 - Authorized RCE POC

simple application with a CVE-2022-45688 vulnerability

simple application with a CVE-2022-45688 vulnerability

🐍 🔍 GuardDog is a CLI tool to Identify malicious PyPI and npm packages

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

An agent to hotpatch the log4j RCE from CVE-2021-44228.

LD_PRELOAD-based tool that hijacks gcc to inject malicious code into binaries during linking, enabling stealthy backdoor deployment without source…

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

A Java Agent that disables Apache Log4J's JNDI Lookup to mitigate CVE-2021-44228 ("Log4Shell").

SafeForge is an open-source mobile app hub built on GitLab that enables developers to build, upload, and share applications in a secure, AI-verified…

Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously…