


XSS Test Swagger 3.14.1 to 3.37.0



he Hunk Companion Plugin for WordPress: Vulnerable to Unauthorized Plugin Installation/Activation (Versions Up to and Including 1.8.4)

A bash automation that exploits the vulnerable endpoints for the Joomla! API 4.0 - 4.2.7

Zita Site Builder <= 1.0.2 - Missing Authorization to Arbitrary Plugin Installation

CVE-2025-3855 - RISE Ultimate Project Manager - IDOR

Swift Performance Lite <= 2.3.6.14 - Missing Authorization to Unauthenticated Settings Export




Clone of suds 0.4 + suds-0.4-CVE-2013-2217.patch

CodePath Assignment for Weeks 7 & 8: CVE-2017-14719, CVE-2019-9787 & Unauthenticated Page/Post Content Modification via REST API

Here's a Python script that checks if the polyfill.io domain is present in the Content Security Policy (CSP) header of a given web application.

Spring Cloud Config CVE-2019-3799|CVE_2020_5410 漏洞检测

retrofit with CVE-2018-1000844

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…