
CVE-2026-71203-PoC
PoC: changedetection.io unauthenticated OpenAPI schema disclosure (CVE-2026-71203, Medium 5.3)

PoC: changedetection.io unauthenticated OpenAPI schema disclosure (CVE-2026-71203, Medium 5.3)

Hack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.

CVE-2026-27944 - Nginx UI Unauthenticated Backup Download & Decryption

Detects CVE-2026-19478 in GitLab CE/EE with a non-destructive Nuclei template that triggers the GraphQL fallback-field method invocation via touch…

Simple JMX RMI scanning tool

SQL Injection in 3CX CRM Integration

Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.

CVE-2025-3855 - RISE Ultimate Project Manager - IDOR

Extends Selenium's Python bindings to give you the ability to inspect requests made by the browser.

A next-generation crawling and spidering framework.

AI-powered bug bounty hunting toolkit that works with or without subscription.

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

Go client to communicate with Chaos DB API.

Tests your WAF with +160 payloads

Hidden parameters discovery suite

Academic purposes only. Attack against Salesforce lightning with guest privilege.

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…