
CVE-2023-32117
Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints

Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints

Spring Cloud Gateway Actuator API SpEL表达式注入命令执行(CVE-2022-22947)批量检测工具

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

CVE-2023-42442 JumpServer Session 录像任意下载漏洞

Milvus 认证安全检测脚本:CVE-2025-64513 (sourceid后门) / CVE-2026-26190 (/expr弱token) / 内部端口53100

CVE-2023-23752 nuclei template

Scans public code repositories and code snippet platforms to extract and validate AI service API keys with real-time dashboard and multi-format…

MCP server that runs SAST scans on local codebases and returns findings with severity and fixes, enabling AI assistants to perform security analysis…

Insecure Permissions WeDayCare

RAGFlow 三洞审计工具 (CVE-2026-28797 / CVE-2026-24770 / CVE-2025-69286)

Apache APISIX 2.12.1 Remote Code Execution by IP restriction bypass and using default admin AIP token

演示 Next.js 中的 Middleware 授權繞過漏洞 (CVE-2025-29927) 允許未經授權的用戶存取受保護的資訊。

Strapi CVE-2026-27886. Leaking sensitive data via relational filtering due to lack of query sanitization

Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.

The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10

The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10

PoC de CVE-2026-35616: control de acceso indebido en FortiClient EMS.

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion