
CVE-2023-45828
RumbleTalk Live Group Chat <= 6.1.9 - Missing Authorization via handleRequest

RumbleTalk Live Group Chat <= 6.1.9 - Missing Authorization via handleRequest

Lightweight Java 8 web framework for building REST APIs and web applications, with built-in routing, static file serving, and template engine support.

XSS Test Swagger 3.14.1 to 3.37.0

Proof-of-concept exploit for CVE-2024-50633, a Broken Object Level Authorization (BOLA) vulnerability in Indico v3.2.9–v3.3.2, enabling unauthorized…

Proof-of-concept exploit for CVE-2023-31719, demonstrating SQL injection in the FUXA web application's /api/signin endpoint via a crafted JSON…

A bash automation that exploits the vulnerable endpoints for the Joomla! API 4.0 - 4.2.7

Proof-of-concept exploit for CVE-2024-26026: unauthenticated SQL injection in F5 BIG-IP Next Central Manager API, enabling remote data extraction and…

Zita Site Builder <= 1.0.2 - Missing Authorization to Arbitrary Plugin Installation

Swift Performance Lite <= 2.3.6.14 - Missing Authorization to Unauthenticated Settings Export

Lightweight Java 8 web framework with routing, filters, and static file serving. Includes security advisory for older versions and CRUD API examples.

he Hunk Companion Plugin for WordPress: Vulnerable to Unauthorized Plugin Installation/Activation (Versions Up to and Including 1.8.4)

CVE-2025-3855 - RISE Ultimate Project Manager - IDOR

Clone of suds 0.4 + suds-0.4-CVE-2013-2217.patch

CodePath Assignment for Weeks 7 & 8: CVE-2017-14719, CVE-2019-9787 & Unauthenticated Page/Post Content Modification via REST API

Type-safe HTTP client for Android and Java with annotation-based API binding, converter support, and integration with OkHttp for network…

A proof-of-concept exploit for **CVE-2026-30824**, a critical authentication bypass vulnerability in Flowise that exposes NVIDIA NIM API endpoints…

Command-line security assessment framework for React and Next.js applications, analyzing React Server Components for misconfigurations, with…

Proof-of-concept exploit for CVE-2026-26012, demonstrating an authenticated organization collection permissions bypass and cipher enumeration in…