
CVE-2025-67923
JetEngine <= 3.7.7 — Unauthenticated Stored Cross-Site Scripting via CCT REST API

JetEngine <= 3.7.7 — Unauthenticated Stored Cross-Site Scripting via CCT REST API

Minimal Python PoC for CVE-2026-40179: injects a malicious metric name via unauthenticated Prometheus remote_write to trigger stored XSS in the web…


A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.

Idempotent functions for IBM Security Appliance REST APIs. Currently covering ISAM and ISDS Appliances.

Application Security Verification Standard

An open source threat modeling tool from OWASP

OPNsense GUI, API and systems backend

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…







The simple PoC of CVE-2023-27587