An ongoing & curated collection of awesome software practices and remediation, libraries and frameworks,payloads and techniques, best guidelines and technical resources about Application Security
-
Updated
Sep 23, 2023 - Python
An ongoing & curated collection of awesome software practices and remediation, libraries and frameworks,payloads and techniques, best guidelines and technical resources about Application Security
A security specification on Nuclear Ad Bombs, and why operating systems shouldn't have embedded ads.
WordPress Security Advisories. Add this package to prevent vulnerable WordPress packages from being installed.
Interim PowerShell ACL mitigation script & conceptual C++ security patch for the "ShieldBreak" Windows Defender LPE Zero-Day (Windows 11 / Server 2025). Maintained by Nathan Wosnack (UBITQUITY / NETTWERKED).
CVE-2026-50131 / GHSA-xw9q-2mv6-9fr8: Fedify incomplete SSRF mitigation advisory landing page
CVE-2026-50181 / GHSA-fg23-3346-88f5: Langroid path traversal advisory landing page
CVE-2026-54520 / GHSA-cm8g-8jfq-887p: ai-agent-automation workflow path traversal advisory landing page
CVE-2026-13152: Custom Fields Account Registration For WooCommerce Unauthenticated Privilege Escalation PoC & Advisory by Huynh Kien Minh (MinhHK).
CSAF (Common Security Advisory Framework) Perl Toolkit
Defensive research notes for CVE-2026-5950, a BIND 9 resolver DoS vulnerability credited to Billy Baraja (BielraX).
CVE-2026-54519 / GHSA-qv97-83w4-ff86: ai-agent-automation memory authorization advisory landing page
A Go client for the GitHub Global Security Advisories API, a public feed of security advisories that affect open source ecosystems (npm, Maven, Go, etc.). This package allows you to list and retrieve advisory metadata without authentication (public data only).
A security advisory on the growing, but overlooked threat of malicious QR code overlays targeting industries such as travel, hotel, personal banking, restaurant, clinics, and more.
CAN-2026-2036559 - Indirect Prompt Injection to RCE (CVSS 4.0: 10.0 CRITICAL) in ArchiveBox OpenCode AI agent. Untrusted archived content reaches LLM execution context with full PTY access. No authentication required.
CPK-2026-005 threat advisory: Google Workspace invitation phishing targeting Web3 founders (TLP:CLEAR).
CVE-2026-67401 cPanel & WHM EmailTrack SQL Injection — IOC scanner, compromise detection, patch verification, incident response and remediation toolkit.
Penetration Tester portfolio. As a Security Researcher, I provided ethical hack disclosures for organizations like NASA and Intel. Expert in web security, vulnerability research, and helping businesses fix website flaws. Focused on professional-grade penetration testing.
To associate your repository with the security-advisory topic, visit your repo's landing page and select "manage topics."