
CVE-2023-31719
Proof-of-concept exploit for CVE-2023-31719, demonstrating SQL injection in the FUXA web application's /api/signin endpoint via a crafted JSON…

Proof-of-concept exploit for CVE-2023-31719, demonstrating SQL injection in the FUXA web application's /api/signin endpoint via a crafted JSON…

Zita Site Builder <= 1.0.2 - Missing Authorization to Arbitrary Plugin Installation

he Hunk Companion Plugin for WordPress: Vulnerable to Unauthorized Plugin Installation/Activation (Versions Up to and Including 1.8.4)

Proof-of-concept exploit for CVE-2024-26026: unauthenticated SQL injection in F5 BIG-IP Next Central Manager API, enabling remote data extraction and…

Swift Performance Lite <= 2.3.6.14 - Missing Authorization to Unauthenticated Settings Export

Lightweight Java 8 web framework with routing, filters, and static file serving. Includes security advisory for older versions and CRUD API examples.

Jenkins plugin for automated mobile app testing via Perfecto cloud, managing secure tunnel connections and app uploads within CI/CD pipelines.

Python-based Burp Suite extension is designed to detect the presence of CVE-2025-31324

A bash automation that exploits the vulnerable endpoints for the Joomla! API 4.0 - 4.2.7

Lightweight Java 8 web framework for building REST APIs and web applications, with built-in routing, static file serving, and template engine support.

Here's a Python script that checks if the polyfill.io domain is present in the Content Security Policy (CSP) header of a given web application.

Spring Cloud Config CVE-2019-3799|CVE_2020_5410 漏洞检测

CodePath Assignment for Weeks 7 & 8: CVE-2017-14719, CVE-2019-9787 & Unauthenticated Page/Post Content Modification via REST API

Type-safe HTTP client library for Android and Java, enabling REST API communication with annotation-based request configuration and converter support.

Type-safe HTTP client for Android and Java with annotation-based API binding, converter support, and integration with OkHttp for network…

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

Terminal-based HTTP intercepting proxy with TUI for capturing, inspecting, and modifying requests in real time, plus a Repeater for resending and…