
CVE-2022-24112-POC
Apache APISIX 2.12.1 Remote Code Execution by IP restriction bypass and using default admin AIP token

Apache APISIX 2.12.1 Remote Code Execution by IP restriction bypass and using default admin AIP token

演示 Next.js 中的 Middleware 授權繞過漏洞 (CVE-2025-29927) 允許未經授權的用戶存取受保護的資訊。

Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.

The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10

The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10

The vulnerability exists in the Student Payment API. The application fails to properly validate whether the user requesting a receipt is authorized…

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

Demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI's chat API, allowing attackers to consume other users'…

Global API Integrity Assessor

Swift Performance Lite <= 2.3.6.14 - Missing Authorization to Unauthenticated Settings Export

Python-based Burp Suite extension is designed to detect the presence of CVE-2025-31324

Zita Site Builder <= 1.0.2 - Missing Authorization to Arbitrary Plugin Installation

CVE-2025-3855 - RISE Ultimate Project Manager - IDOR

Here's a Python script that checks if the polyfill.io domain is present in the Content Security Policy (CSP) header of a given web application.

Spring Cloud Config CVE-2019-3799|CVE_2020_5410 漏洞检测

AI-powered bug bounty hunting toolkit that works with or without subscription.

AI-powered bug bounty hunting toolkit that works with or without subscription.

PoC de CVE-2026-35616: control de acceso indebido en FortiClient EMS.