
CVE-2026-27886
Strapi CVE-2026-27886. Leaking sensitive data via relational filtering due to lack of query sanitization

Strapi CVE-2026-27886. Leaking sensitive data via relational filtering due to lack of query sanitization

Code to reproduce the vulnerability individually

The code for personally reproducing the corresponding vulnerability

Simple JMX RMI scanning tool

YAMCS yamcs-core < 5.12.7 lacks rate limiting on POST /auth/token. An unauthenticated attacker can perform unlimited brute-force attempts against any…

Nuclei detection template for CVE-2026-41473, an unauthenticated read/write API access flaw in CyberPanel AI Scanner before 2.4.4. Uses two HTTP…




[CVE-2016-4014] SAP Netweaver AS JAVA UDDI Component XML External Entity (XXE)

CVE-2023-23752 nuclei template

Insecure Permissions WeDayCare

FOSSBilling CVE-2026-53647 & CVE-2026-53646 PoC — Unauthenticated API key disclosure & password reset token reuse

CVE-2026-24136 | Lab khai thác lỗ hổng IDOR trên Saleor GraphQL - query order() không kiểm tra xác thực, lộ toàn bộ PII (email, địa chỉ, SĐT) của…

Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.

SQL Injection in 3CX CRM Integration


Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain