
CVE-2025-14598
CVE-2025-14598 Remote Unauthenticated SQL Injection leading to Remote Code Execution.

CVE-2025-14598 Remote Unauthenticated SQL Injection leading to Remote Code Execution.

Reverse engineering of the engine powering the PriPara games on arcade.

CVE-2022-23779 is a security vulnerability in Zoho ManageEngine Desktop Central ,Testing for CVE-2022-23779 using curl

PoC and Disclosure for CVE-2023-7231 – Memcached Gopher RCE chain


A critical Server-Side Template Injection (SSTI) vulnerability exists in the X-Trading Portal v1.4.2 dashboard metadata rendering engine. The flaw…

Internal network honeypot for detecting if an attacker or insider threat scans your network for log4j CVE-2021-44228

SquirrellyJS mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration…


CVE-2025-29927 is a critical vulnerability in Next.js, a popular React-based web framework. The flaw exists in how the middleware feature handles…

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer


It is a simple script to automate internal port scanning dueto SSRF in requests-baskets v 1.2.1. this script can also assisst in solving 'SAU'…

A transparent PII redaction proxy for LLM API traffic. Sits between an application and an LLM provider (currently Anthropic), pseudonymizing…

This is an incident response playbook we created for the Vercel April 2026 compromise

A ESP32-S3–based usb keylogger with wifi, easy DIY-able with widely available hardware.

MCP is being adopted rapidly. Security guidance is lagging behind. This checklist gives security engineers, platform teams, and technical leaders a…