
CVE-2026-46726
Reproducer for CVE-2026-46726: Apache Camel camel-vertx-websocket unfiltered inbound header injection enabling SSRF and secret disclosure via…

Reproducer for CVE-2026-46726: Apache Camel camel-vertx-websocket unfiltered inbound header injection enabling SSRF and secret disclosure via…

CVE-2026-67595 — Embedded malicious JavaScript (spyware) in VaahCMS 2.0.0–2.3.4 official releases. CVSS 8.1. Advisory + detection.

Proof-of-concept exploit for CVE-2026-37068: arbitrary file write in Veno File Manager 4.4.9 via authenticated POST request to /vfm-admin/index.php.

Stored XSS in TastyIgniter v3.0.7 Restaurtant CMS

Go-based scanner that detects DOMPurify sanitizer bypass (CVE-2026-47423) via logic fingerprinting on minified production JavaScript bundles,…


This repository hosts a multimodal web attack dataset (MWAD) to advance AI-driven threat detection research.

PoC reproducer for CVE-2026-49365 (Apache Camel camel-netty-http / camel-undertow): muteException defaults to false, so an uncaught exception's full…

CyberDefenders JetBrains Lab

PoC for CVE-2024-1512 in MasterStudy LMS WordPress Plugin.

Cisco CVE-2023-20198

Joomla Unauthorized Access Vulnerability

CVE-2025-5777 Research writeup

Defensive mitigation and auditing toolkit for CVE-2026-54420 in LiteSpeed cPanel plugin, providing symlink detection, IOC hunting, and remediation…

Proof-of-concept for a reflected cross-site scripting (XSS) vulnerability in Hotel Druid 3.0.2, demonstrating arbitrary JavaScript execution via…

Detection method for Exim vulnerability CVE-2024-39929

Modern Events Calendar Lite <= 7.33.0 — Unauthenticated SQL Injection

Docker lab for reproducing and studying CVE-2023-44487 (HTTP/2 Rapid Reset) for thesis research, providing a controlled environment for vulnerability…