
CVE-2025-70545
Stored XSS proof-of-concept for PPC (Belden) ONT 2K05X router firmware v1.1.9_206L, with reproduction steps and mitigation guidance for the…

Stored XSS proof-of-concept for PPC (Belden) ONT 2K05X router firmware v1.1.9_206L, with reproduction steps and mitigation guidance for the…

Educational resource on Cross-site Scripting (XSS) attack techniques, covering non-persistent, persistent, and DOM-based vectors with practical…

Decrypt and re-encrypt Laravel session cookies to exploit insecure PHP deserialization for remote code execution.

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

A static analysis security vulnerability scanner for Ruby on Rails applications

Major Security Vulnerability on PrestaShop Websites - CVE-2022-31101

A request parameter filter solution for Struts 1 CVE-2014-0114 based on the work of Alvaro Munoz and the HP Fortify team

Local-first macOS research browser built on a custom Brave build that captures network traffic, fingerprints, scripts, and runtime evidence for…

UnauthScout is an OSINT (Open Source Intelligence) tool developed in Bash for passive exploration of assets on version control platforms (GitLab and…

Proof-of-concept exploit for CVE-2023-29007, a Git arbitrary configuration injection vulnerability. Demonstrates exploitation on Windows systems for…

Ruby on Rails是一个 Web 应用程序框架,是一个相对较新的 Web 应用程序框架,构建在 Ruby 语言之上。这个漏洞主要是由于Ruby on Rails使用了指定参数的render…

Vulnerabilities in the Git node allowed authenticated users with permission to create or modify workflows to execute arbitrary system commands or…

Go-based scanner that detects DOMPurify sanitizer bypass (CVE-2026-47423) via logic fingerprinting on minified production JavaScript bundles,…

Researching on the vulnrability CVE-2023-26136

SPH Engineering UgCS 5.13.0 is vulnerable to Arbitary code execution. This is the public refrence to be used on CVE site

CVE-2025-55182 and CVE-2025-66478

Java library for XML serialization and deserialization, with a focus on the CVE-2020-26217 deserialization vulnerability exploit.

AI Code Security — four agents that catch what SAST misses in AI-generated code. Built on GitLab Duo Agent Platform.