
keyhacks
Curated collection of commands to validate leaked API keys from bug bounty programs and penetration tests, covering 80+ services including AWS,…

Curated collection of commands to validate leaked API keys from bug bounty programs and penetration tests, covering 80+ services including AWS,…

The Shadow Daemon web application firewall server



A PoC exploit for CVE-2020-13945 - Apache APISIX Remote Code Execution (RCE)

Apache APISIX batch-requests RCE(CVE-2022-24112)


A "Mishandling of Input to API" or "Exposed Dangerous Method or Function" vulnerability in PrintixService.exe, in Kofax Printix's "Printix Secure…

[CVE-2020-17518] Apache Flink RESTful API Arbitrary File Upload via Directory Traversal

gRPC-Go RBAC Authorization Policy Bypass via Missing `:path` Slash (Auth Bypass)

PoC reproducer for CVE-2026-55993 (Apache Camel camel-atmosphere-websocket): the WebSocket consumer copies connection query parameters onto the…

Missing Authorization in inseriswiss inseri core inseri-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue…

Minimal Python PoC for CVE-2026-40179: injects a malicious metric name via unauthenticated Prometheus remote_write to trigger stored XSS in the web…

Security Advisory: Stored Cross-Site Scripting Via Agent Messages Leading To Session Token Theft (openclaw-dashboard)

PoC exploit for unauthenticated RCE in EITS Admin Dashboard v2.4.0 via command injection in /api/v1/debug, allowing arbitrary OS command execution on…

This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by…