


ArmourBird CSF - Container Security Framework

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

CVE-2026-67598 — Emlog Pro: disabled TLS certificate validation in AI assistant (MITM → API-key theft). CWE-295, CVSS 9.1. Reported by @IlhomjonR.

The simple PoC of CVE-2023-27587

PoC for CVE-2026-49230: Apache APISIX jwe-decrypt authentication bypass (missing AES-GCM tag validation, CWE-354, CVSS 9.1)

Sensitive Information Exposure via API in LearnDash.

Sensitive Information Exposure via assignments in LearnDash.

WPQA < 5.5 - Unauthenticated Private Message Disclosure


CVE-2020-9483 OR CVE-2020-13921


CVE-2020-8554: Man in the middle using LoadBalancer or ExternalIPs

Traccar GPS Tracking System

List of API's for gathering information about phone numbers, addresses, domains etc

Automagically reverse-engineer REST APIs via capturing traffic

AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation
