
CVE-2022-30507-PoC
PoC for Arbitrary Code Execution in Notable

PoC for Arbitrary Code Execution in Notable

CVE-2026-39154, Stored XSS in CometChat JS SDK

Proof-of-concept for CVE-2024-4367 that generates a malicious PDF to exploit arbitrary JavaScript execution in PDF.js.

Next.js RSC RCE Exploit Tool (CVE-2025-55182)

Technical dossier on the DPRK-linked PolinRider supply-chain attack, documenting obfuscated JS payload injection, git history manipulation, C2…

JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.

Haraj Script 3.7 - Authenticated Stored XSS

POC for PDF JS' CVE-2024-4367 vuln

Gitlab v12.4.0-8.1 RCE

Regular expression matching for URL's. Maintained, safe, and browser-friendly version of url-regex. Resolves CVE-2020-7661 for Node.js servers.

CVE-2024-4367 arbitrary js execution in pdf js

Exploit of CVE-2021-23639 for the vulnerable library 'md-to-pdf' in JS

"qs" prototype poisoning vulnerability ( CVE-2022-24999 )

Proof-of-concept exploit for CVE-2025-53964: remote file read/write via malicious XDXF dictionary in GoldenDict 1.5.0/1.5.1, leveraging unsanitized…

PoC Exploit CVE-2018-6389

Chrome V8 RCE exploit for CVE-2021-30632 targeting Windows systems. Tested on Chrome 91-93. Includes JS POC and in-the-wild bug analysis reference.

Multi-language PoC (Python · Go · JS · C) and technical documentation for CVE-2025-63353, a critical predictable-default-PSK vulnerability in…

Detailed analysis of CVE-2024-28397, a sandbox escape vulnerability in js2py enabling RCE via Python object traversal. Includes code analysis, PoC,…