
wp2shell
unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)
api-securityexploitationpassword-cracking+4

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)
Documentation of CVE-2026-31283: an email bombing vulnerability in Totara LMS's forgot password API due to missing rate limiting, allowing…

This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by…

PHP 8.4+ security library (mirror)

NebulousAD automated credential auditing tool.