
CVE-2026-19478-PoC
Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

List of regex for scraping secret API keys and juicy information.



Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

Burp Plugin for Secret Matching

Appspec YML and YAML leaks

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.


Security advisory: Azure APIM Developer Portal allows cross-tenant account registration by bypassing UI signup restrictions. Reported to MSRC twice -…

Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan,…

The simple PoC of CVE-2023-27587

CVE-2026-32646: Missing Authentication on Admin Device Endpoint — Gardyn Home Kit (ICSA-26-055-03)

CVE-2026-28766: Missing Authentication on User Account Endpoint — Gardyn Home Kit (ICSA-26-055-03)

Authenticated API Key Exposure in Nagios Log Server 2024R1.3.1

Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

WPQA < 5.5 - Unauthenticated Private Message Disclosure