
MISP
MISP (core software) - Open Source Threat Intelligence and Sharing Platform

MISP (core software) - Open Source Threat Intelligence and Sharing Platform

Fortinet FortiSandbox 4.4.0-4.4.8 - OS Command Injection via tracer-behavior Endpoint

general purpose workaround for the log4j CVE-2021-44228 vulnerability

proof-of-concept (PoC) for linux dists based on Debian, CentOS and RedHat - exploit 1

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

Creosote is our solution to searching for the tarfile vulnerability described by CVE-2007-4559.

Remote Code Execution vulnerability on ArcSight Logger

XSS Vulnerability in Rittal

Proof-of-concept exploit for authenticated OS command injection (CWE-78) in Cacti ≤1.2.30, achieving remote code execution with CVSS 7.2.

Exploit for Apache Struts CVE-2017-9805, a remote code execution vulnerability in the REST plugin. Enables penetration testing and security…

Hack The Box Writeup for Retired Challenge ReactOOPS - Complete solution and educational guide to CVE-2025-55182/CVE-2025-66478 (React2Shell RCE).…

Proof-of-concept exploit for CVE-2019-9653 demonstrating unauthenticated remote code execution as root on NUUO NVR devices via vulnerable PHP scripts.

eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's…

PoC

This repository contains a solution for the CVE-2023-26136 vulnerability.

A request parameter filter solution for Struts 1 CVE-2014-0114 based on the work of Alvaro Munoz and the HP Fortify team

Continuous fuzzing solution integrated into CI workflows to find vulnerabilities in code changes and batch runs, supporting multiple languages and CI…

Windows privilege escalation lab that recreates CVE-2023-27470's arbitrary file deletion bug, with vulnerable executable, source, solution, and a…