
CVE-2022-24112-POC
Apache APISIX 2.12.1 Remote Code Execution by IP restriction bypass and using default admin AIP token

Apache APISIX 2.12.1 Remote Code Execution by IP restriction bypass and using default admin AIP token

Ultimate Gift Cards for WooCommerce <= 3.0.6 - Missing Authorization to Infinite Money Glitch

演示 Next.js 中的 Middleware 授權繞過漏洞 (CVE-2025-29927) 允許未經授權的用戶存取受保護的資訊。



Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.



Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation

Spring-Cloud-Gateway-CVE-2022-22947

CVE-2024-11972 in Hunk Companion <1.9.0 allows unauthenticated attackers to exploit insecure REST API endpoints and install vulnerable plugins,…

Magical Addons For Elementor <= 1.2.1 - Authenticated (Subscriber+) Server-Side Request Forgery

一个由AI生成的漏洞验证应用

ChilliCream Nitro GraphQL version 28.0.13 is vulnerable to multiple Stored Cross Site Scripting (XSS) Vulnerabilities

The vulnerability exists in the Student Payment API. The application fails to properly validate whether the user requesting a receipt is authorized…
