
CVE-2024-46627
Proof-of-concept for CVE-2024-46627: unauthenticated REST API access control bypass in BECN DATAGERRY v2.2 allowing arbitrary user settings…

Proof-of-concept for CVE-2024-46627: unauthenticated REST API access control bypass in BECN DATAGERRY v2.2 allowing arbitrary user settings…

Proof-of-concept for CVE-2025-492030: account takeover via session token validation bypass in SecureVPN API endpoint /api/v1/authenticate.

Proof-of-concept for CVE-2025-30144: JWT issuer validation bypass in fast-jwt library allowing attackers to forge tokens with array-based iss claims.

CVE-2016-1000229

Python-based proof-of-concept script demonstrating CVE-2018-25031 XSS vulnerability in Swagger UI using Selenium for automated detection across…

GraphQL vulnerability disclosure: CVE-2023-26144

One missing function call on the route registration was enough to turn the MCP interface into an unauthenticated RCE gateway.

Documentation of CVE-2025-56223, a denial-of-service vulnerability in Ascertia SigningHub's Upload Document API, allowing unrestricted file uploads…

Proof of concept of CVE-2025-62727 that can cause denial-of-service in FastAPI (based Starlette <= 0.48.0)

Non-destructive vulnerability scanner for Nginx-UI MCP Endpoint Authentication Bypass (CVE-2026-33032)

CVE on FlagForgeCTF on versions v2.0.0 to v2.3.1. Upgraded to version 2.3.2 to fix the issue.

NAXSI is an open-source, high performance, low rules maintenance WAF for NGINX

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)