
WebMirage
Adversarial image attacks on vision-language web agents, from visual grounding to browser execution

Adversarial image attacks on vision-language web agents, from visual grounding to browser execution

WordPress wp2shell pre-auth RCE exploit kit (CVE-2026-63030 + CVE-2026-60137)

Spring Framework CVE-2022-22965 本地影响条件验证、版本升级修复与复测项目

Hands-on lab demonstrating CVE-2024-38819 Spring Framework path traversal vulnerability with vulnerable and patched Spring Boot deployments for…

Fuzzing Framework for Modules in Apache HTTPD Server

Cursor plugin for Hono v4 (TypeScript edge web framework). 59 LLM regressions with BAD/CORRECT pairs. Pinned to hono ^4.12.19 (>= 4.9.7 for…

JAW: A Graph-based Security Analysis Framework for Client-side JavaScript

ReactGuard provides framework- and vulnerability-detection tooling for CVE-2025-55182 (React2Shell)

Exploit for CVE-2011-4367 targeting Apache MyFaces JSF implementation, demonstrating a remote code execution vulnerability in the Jakarta Faces…

Lightweight Java 8 web framework for building REST APIs and web applications, with built-in routing, static file serving, and template engine support.

Lightweight Java 8 web framework with routing, filters, and static file serving. Includes security advisory for older versions and CRUD API examples.

Exploit for CVE-2018-12542 in Vert.x-Web, a Java web framework. Demonstrates a path traversal vulnerability allowing unauthorized access to static…

PoC and fix for CVE-2024-38828: Spring Framework DoS via Content-Length manipulation in ByteArrayHttpMessageConverter. Includes load testing,…

Example exploitable scenarios for CVE-2024-22243 affecting the Spring framework (open redirect & SSRF).

Kurukshetra - A framework for teaching secure coding by means of interactive problem solving.

Curated Java web framework vulnerability (CVE-2016-5394) for Apache Sling, designed for security testing, exploitation practice, and vulnerability…

Educational repository demonstrating XSS vulnerabilities in Django Rest Framework applications. Contains intentionally vulnerable code to teach…

"Sucosh" is an automated Source Code vulnerability scanner and assessment framework for Python(Flask-Django) & NodeJs capable of performing code…