
osv.dev
Open source vulnerability DB and triage service.

Open source vulnerability DB and triage service.

Demonstrate the unauthenticated remote code execution vulnerability in the RSFiles! Joomla component through an arbitrary file upload.

Vulnerable app with examples showing how to not use secrets

An open source threat modeling tool from OWASP

Aggregates software supply chain security metadata (SBOMs, attestations, vulnerabilities) into a queryable graph database for audit, policy, and risk…

📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.

Python-based interactive packet manipulation library for forging, decoding, sending, capturing, and analyzing network packets across a wide range of…

Automatic SQL injection and database takeover tool

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Technical deep-dives and root cause analyses of recently disclosed CVEs - reverse engineering patches, building proof-of-concepts, and documenting…

🧠 Automatically collects and updates public Proof-of-Concept (PoC) exploits from poc-in-github.motikan2010.net

Proof-of-concept exploit for CVE-2026-39987, a pre-authentication RCE in Marimo's terminal WebSocket endpoint. Demonstrates unauthenticated command…

Proof-of-concept and technical analysis for CVE-2026-85046, a V8 type confusion in inline Array.prototype.sort, including root cause, patch diff, and…

Linux operating system for embedded devices with writable filesystem, package management, and build framework. Enables custom firmware creation for…

Proof-of-concept exploit for CVE-2026-85046 in Chrome 152.0.7977.75, demonstrating type confusion in sort() to achieve arbitrary code execution via a…

Proof-of-concept exploit for CVE-2026-29782, chaining SQL injection and PHP object injection to achieve remote code execution in OpenSTAManager.…